Security advisories

The newest 300 of 1222 advisories the tracked projects have published, with the release that carries the fix. Severity is the one its publisher assigned. Nothing here is our judgement. Each product keeps its own full register, linked below.

Advisories
1222 across 42 products
critical
61
high
457
medium
549
low
88
Newest
9 Oct 2026 2 days ago

An advisory is listed only when its publisher has published it with an identifier. Release notes that use the word security without one are not listed here, because a security page is worth reading only if every line on it can be checked. 1027 of these carry a CVE, and 619 are matched to the release in the archive that fixed them.

This page is a copy of what the publishers published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Every product’s own register

1222 advisories, all of them
n8n210 advisories
newest 2026oldest 2025
vLLM104 advisories
newest 2026oldest 2025
Keycloak83 advisories
newest 2026oldest 2021
Next.js69 advisories
newest 2026oldest 2020
Hono52 advisories
newest 2026oldest 2023
Redis47 advisories
newest 2026oldest 2021
Astro44 advisories
newest 2026oldest 2024
Deno40 advisories
newest 2026oldest 2021
Grafana28 advisories
newest 2023oldest 2021
Moby26 advisories
newest 2026oldest 2021
Vite22 advisories
newest 2026oldest 2023
Strapi21 advisories
newest 2026oldest 2023
Dify21 advisories
newest 2026oldest 2025
Fastify15 advisories
newest 2026oldest 2022
Svelte13 advisories
newest 2026oldest 2024
Zed12 advisories
newest 2026oldest 2025
Valkey12 advisories
newest 2026oldest 2024
NestJS10 advisories
newest 2026oldest 2025
Laravel9 advisories
newest 2026oldest 2021
React8 advisories
newest 2026oldest 2025
Vitest7 advisories
newest 2026oldest 2025
Rust6 advisories
newest 2025oldest 2019
DuckDB3 advisories
newest 2025oldest 2024
esbuild3 advisories
newest 2026oldest 2025
Qdrant2 advisories
newest 2026oldest 2026
Neovim1 advisory
newest 2023oldest 2023
PostHog1 advisory
newest 2023oldest 2023
FastAPI1 advisory
newest 2021oldest 2021
Vue.js1 advisory
newest 2026oldest 2026
Prisma1 advisory
newest 2021oldest 2021

Newest 300 across every product

vLLMmedium

Unvalidated stop_token_ids causes engine crash (DoS) and out-of-bounds GPU write

GHSA-w9r6-29q4-pvprFixed in 0.29.0Advisory
vLLMhigh

Remote DoS in vLLM via allowed_token_ids Speculative-Decoding Metadata Mismatch

GHSA-8c65-hq7q-r7jmFixed in 0.18.0Advisory
vLLMhigh

Frame-count cap bypass in VideoMediaIO.load_base64 for video/jpeg via media_io_kwargs.video.num_frames

GHSA-4m6g-h9mv-wqjcFixed in 0.31.0Advisory
vLLMmedium

Remote DoS in disaggregated multimodal /inference/v1/generate via malicious kwargs_data / mm_placeholders

GHSA-34qw-q2h2-jp3mFixed in 0.30.0Advisory
vLLMhigh

Nemotron-VL processors disable Pillow decompression-bomb guard globally, enabling unauthenticated DoS

GHSA-mm38-5g96-7j6xFixed in 0.25.0Advisory
vLLMhigh

SSRF via X-Request-Id header drives P2pNcclConnector outbound ZMQ+NCCL pair, leaking KV-cache tensors

GHSA-vfp2-c8pq-v6h6Fixed in 0.24.0Advisory
vLLMmedium

Multimodal chat audio decoding bypasses the decompression-bomb duration limit

GHSA-r45p-7qwx-qwjwFixed in 0.24.0Advisory
vLLMmedium

Rust gRPC Generate accepts out-of-vocabulary prompt token IDs and can terminate EngineCore

GHSA-w2v2-5662-8v5qFixed in 0.24.0Advisory
vLLMmedium

Rust gRPC output_candidates.token_ids bypasses logprob_token_ids limits and can terminate EngineCore

GHSA-6pgw-f3pv-4h8qFixed in 0.24.0Advisory
vLLMmedium

Rust gRPC CandidateTokens.top_n bypasses max_logprobs and can terminate EngineCore

GHSA-rwfw-xvg3-3937Fixed in 0.24.0Advisory
Vitemedium

First 4 bytes of files outside of `server.fs` setting is exposed by `?vite-wasm-instance`

GHSA-vfpm-58rq-9qcgFixed in 8.3.3Advisory
Vitemedium

Files outside `server.fs.allow` could be served when project paths match system paths on non-Windows machine

GHSA-rq7h-c2jc-7f22Fixed in 8.3.3Advisory
vLLMhigh

DoS via unvalidated mm_processor_kwargs in multimodal image processors (Isaac, InternVL, H2OVL, etc.)

GHSA-gx7p-2j49-hfq4Fixed in 0.31.0Advisory
vLLMmedium

Caller-controllable values become or collide with shared cache keys, enabling cross-request cache aliasing (2 sites: multimodal EXIF hash and prefix-cache extra keys)

GHSA-rh6f-3x46-j33qFixed in 0.31.0Advisory
vLLMhigh

Request-controlled mm_processor_kwargs.code_revision allows remote code execution

GHSA-h3rc-6mm3-gc2mFixed in 0.31.0Advisory
vLLMhigh

MOSS-Audio request-controlled processor cache permits remote memory exhaustion

GHSA-823j-m4cj-hmjfFixed in 0.31.0Advisory
vLLMmedium

An oversized min_tokens in one request hangs the vLLM engine while /health stays green

GHSA-4xqp-c3mv-qff7Fixed in 0.31.0Advisory
vLLMmedium

Forged multimodal UUID + P0/P1 processor-cache eviction drift: unauthenticated remote crash of the whole vLLM engine

GHSA-p92p-rxj5-7p2xFixed in 0.31.0Advisory
vLLMlow

V1 InputBatch.condense leaves a stale allowed_token_ids mask on recycled batch rows

GHSA-6cxc-2vcg-w5qcFixed in 0.31.0Advisory
Qdranthigh

Read-only API key and JWTs accepted on internal gRPC API when enforce_internal_auth is enabled

GHSA-3gph-6c29-p29vFixed in 1.19.2Advisory
n8nhigh

Execute Sub-workflow Inline JSON Allows Member to Spoof Workflow Identity for Credential Authorization, Static Data, and Error-Workflow Dispatch

GHSA-866p-xg8v-g2q7Fixed in 1.123.83Advisory
n8nmedium

Unauthenticated Cross-Project Workflow Execution via Webhook Path-Only Resolution

GHSA-4c7j-qff5-r9cxFixed in 2.41.4Advisory
n8nhigh

Shared-Workflow Credential Check Misses Agent Node Parameter Credentials

GHSA-x25p-9mr6-cwgpFixed in 2.41.4Advisory
n8nhigh

n8n Chat Trigger Stored XSS via customCss Parameter on Hosted-Chat Page

GHSA-x5cw-hm7v-q7mjFixed in 2.41.4Advisory
n8nhigh

Send-and-Wait HMAC Bypass Allows Unauthenticated Approval of Waiting Executions

GHSA-728h-pmr2-7cghFixed in 2.41.4Advisory
n8nhigh

Code Execution in the Git Node Log Operation via Unneutralized Repository Configuration

GHSA-x8wx-g24x-3549Fixed in 2.41.4Advisory
n8nhigh

Unauthenticated Unbounded OAuth Client Persistence via the Authorize Endpoint

GHSA-3qcw-p65v-c7vqFixed in 2.41.4Advisory
n8nhigh

Shared Prototype Mutation Through the MCP Workflow-Validation Interpreter Allows Owner Account Takeover

GHSA-5jr4-xmvf-frmjFixed in 2.41.4Advisory
n8nmedium

Cross-User Agent Chat Resume Allows Hijacking Another User's Pending Tool Approval

GHSA-p3pg-xw4f-m72cFixed in 2.41.4Advisory
n8nhigh

SQL Injection in the Microsoft SQL Node via Expression Interpolation into the Query Field

GHSA-5qpp-pqww-h7fpFixed in 2.41.4Advisory
Next.jsmedium

Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass

CVE-2026-94485Fixed in 16.3Advisory
Next.jsmedium

Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitution and persistent denial of service

CVE-2026-94484Fixed in 16.3Advisory
Next.jsmedium

Cache poisoning of SSG and ISR pages in self-hosted Next.js applications

CVE-2026-94543Fixed in 15.5Advisory
Next.jslow

Information disclosure in the Next.js development server's Model Context Protocol endpoint

CVE-2026-94486Fixed in 16.3Advisory
Next.jshigh

Server-Side Request Forgery in Image Optimization

CVE-2026-94483Fixed in 16.3Advisory
Next.jsmedium

Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages

CVE-2026-94544Fixed in 16.3Advisory
Honomedium

`serveStatic` decodes the request path a second time, leading to bypass of middleware on static paths

GHSA-5r4p-p66f-jhc7Fixed in 4.13.11Advisory
vLLMlow

Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle

vLLMmedium

Crafted IAMF audio upload reaches a PyAV/FFmpeg native heap overflow through the speech transcription path — denial of service

GHSA-m52c-39rh-f3gpFixed in 0.29.0Advisory
vLLMmedium

Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core

Open WebUImedium

Any authenticated user can exhaust worker memory via a nested-repetition knowledge-search pattern

GHSA-gww9-mhgj-pfqhFixed in 0.11.4Advisory
Open WebUImedium

Any authenticated user can exhaust server memory via a compressed remote image in a chat message

GHSA-w8j8-jv6j-3m47Fixed in 0.11.4Advisory
Open WebUIhigh

Any authenticated user can steal another user's session token via script embedded in a DOCX preview

GHSA-f9xp-mfmq-x6cgFixed in 0.11.4Advisory
Open WebUImedium

Knowledge base collaborators keep read and delete access to removed files via stale file metadata

GHSA-9cxp-636w-4997Fixed in 0.11.4Advisory
vLLMmedium

Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`

vLLMmedium

Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service

CVE-2026-105756Fixed in 30.0.0Advisory
vLLMmedium

Scale-out disaggregated multimodal transport trusts caller-supplied features — shared EngineCore denial of service, encoder-cache poisoning, and transport integrity loss (5 sites)

vLLMmedium

Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites)

vLLMmedium

Unbounded Prometheus label cardinality from attacker-controlled HTTP method tokens in the vLLM Rust frontend metrics middleware (unauthenticated denial of service)

vLLMmedium

Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach

n8nmedium

Approval Bypass in the Send and Wait Node's Approve Within Chat Mode

GHSA-342v-gmh6-738jFixed in 2.39.6Advisory
n8nhigh

Dynamic Credentials Authorize Endpoint Leaks Session Token to Attacker-Controlled Resolver

GHSA-rx55-8qhx-4hwxFixed in 2.39.6Advisory
n8nmedium

Unescaped Parameter Interpolation into Third-Party Query Languages Enables Filter Bypass and Bulk Data Disclosure

GHSA-5pg9-2vqx-r6jmFixed in 2.39.6Advisory
n8nhigh

Path Traversal in the n8n Node Redirects Public API Calls to Unintended Resources

GHSA-89p4-6h98-c7xmFixed in 2.39.6Advisory
n8nhigh

Wekan and Baserow Credentials Leak Account Password to Unvalidated Host via preAuthentication Hook

GHSA-gx6g-2hm7-c4xfFixed in 2.39.6Advisory
n8nhigh

Path Traversal in Signed Resume URL Generation Enables Cross-Project Approval Forgery

GHSA-597w-c3jh-g8fgFixed in 2.39.6Advisory
n8nhigh

Credential Test Endpoint Resolves Project-Scoped Variables from Attacker-Controlled Project ID

GHSA-7gvh-q9w3-wqqxFixed in 2.39.6Advisory
n8nhigh

Community Package Install Validation Bypass via PubSub in Queue Mode Deployments

GHSA-fmmv-p585-7c8xFixed in 2.39.6Advisory
n8nhigh

NoSQL Injection in MongoDB Chat Memory Node Allows Unauthenticated Cross-Session Chat History Disclosure

GHSA-w24g-6454-7w7fFixed in 2.39.6Advisory
n8nhigh

Duplicate Node IDs Bypass Workflow Credential Tamper Guard, Exposing Credentials to a Shared Workflow Editor

GHSA-7gjv-rcf8-x5qcFixed in 1.123.80Advisory
n8nhigh

Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Check

GHSA-9rhv-fhr8-7q5rFixed in 2.39.6Advisory
n8nmedium

Missing Webhook Signature Verification in Webflow Trigger Node Allows Forged Event Injection

GHSA-hwv9-jhc7-f7c4Fixed in 2.39.6Advisory
Fastifymedium

fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses

Kubernetesmedium

StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation

CVE-2026-2270Advisory
Kubernetesmedium

Subpath symlinking on Windows nodes permits NTLM coercion

CVE-2026-76654Advisory
vLLMmedium

Out-of-range `stop_token_ids` with `min_tokens` can kill vLLM EngineCore

GHSA-v5gm-qgmv-gc6cFixed in 0.29.0Advisory
vLLMmedium

Rust HTTP/gRPC stop_token_ids bypass Python vocab-bound fix and can terminate EngineCore

GHSA-qff2-492f-9fm4Fixed in 0.24.0Advisory
vLLMmedium

Disaggregated generate skips decoder prompt-length validation for some multimodal processors

GHSA-3mqx-f33v-vgp9Fixed in 0.29.0Advisory
vLLMmedium

Remote media is fetched and fully materialized before the documented media size / item limits are enforced — remote pre-inference memory and bandwidth exhaustion (4 sites)

GHSA-p6g9-7v3x-m8mvFixed in 0.29.0Advisory
vLLMlow

Sampler Subclass Counter Shadowing Bypasses PyNvVideoCodec Decoder Limits and GPU Memory Accounting

vLLMmedium

Uncontrolled resource consumption: multimodal chat audio decoding ignores `VLLM_MAX_AUDIO_CLIP_FILESIZE_MB`

vLLMmedium

vLLM DoS via unbounded `cache_salt` length: multi-hundred-MB salt stalls the single EngineCore scheduler thread (CPU exhaustion)

Visual Studio Codehigh

Visual Studio Code Restricted Mode bypass via nested configuration objects

CVE-2026-70334Fixed in 1.136.2Advisory
Visual Studio Codecritical

Visual Studio Code Workspace Trust bypass through attacker-controlled services

CVE-2026-81376Fixed in 1.136.2Advisory
Visual Studio Codehigh

Remote code execution through workspace-configured remote agent host connections

CVE-2026-78462Fixed in 1.136.2Advisory
Visual Studio Codemedium

Azure DevOps access token disclosure through GitHub Copilot Chat workspace settings

CVE-2026-81381Fixed in 1.136.2Advisory
Visual Studio Codemedium

Information Disclosure through Automatic Remote Image Fetch in Chat

CVE-2026-81380Fixed in 1.136.2Advisory
Honomedium

hono/jsx renders plain strings unescaped in boundary components, leading to XSS

GHSA-hxh3-vqpv-xpqvFixed in 4.13.7Advisory
Fastifyhigh

fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers

n8nmedium

Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution

CVE-2026-86073Fixed in 2.37.7Advisory
vLLMhigh

Denial of service: a negative token id in `/v1/embeddings` or `/pooling` input kills the vLLM engine via a CUDA device-side assertion

n8nhigh

Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint

CVE-2026-86075Fixed in 2.37.7Advisory
n8nhigh

Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution

n8nmedium

Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket

CVE-2026-86077Fixed in 2.37.7Advisory
n8nmedium

Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter

n8nmedium

Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check

n8nmedium

Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints

CVE-2026-86085Fixed in 2.37.7Advisory
n8nmedium

Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service

CVE-2026-86078Fixed in 2.37.7Advisory
n8nmedium

Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content

CVE-2026-86074Fixed in 2.37.7Advisory
n8nmedium

Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read

n8nmedium

Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers

n8nmedium

GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open

n8nhigh

Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path

n8nmedium

Agent Workflow Tool Bypasses Sub-Workflow Caller Policy

CVE-2026-86996Fixed in 2.37.7Advisory
n8nhigh

Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node

n8nmedium

Improper Authorization in Source Control Push Allows Cross-Project Workflow and Credential Deletion

GHSA-hvrx-jc5j-pg3wFixed in 1.123.76Advisory
n8nhigh

Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution

Vue.jshigh

XSS in @vue/server-renderer via missing CR in attribute-name blacklist

GHSA-g2v6-rqmx-r4w6Advisory
Valkeyhigh

Unauthenticated use-after-free of the Lua interpreter state in Valkey (script debugger command cache)

GHSA-fq2f-crmw-q97rFixed in 9.1.2Advisory
vLLMmedium

Speech-to-text audio decode duration limit bypass via forged header sample rate

vLLMhigh

LlavaOnevision2 processor loader executes attacker model code with `trust_remote_code=False` (inert `trust_remote_code` kwarg to `transformers.get_class_from_dynamic_module`) — RCE from a malicious model

Astromedium

Authorization bypass from missing path-segment boundary check when stripping the configured base

Honomedium

Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

Honomedium

Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory

Next.jscritical

Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

GHSA-2xp9-vwfh-vxw4Fixed in 16.3.3Advisory
vLLMmedium

Unauthenticated audio decompression-bomb DoS in /v1/chat/completions: VLLM_MAX_AUDIO_DECODE_DURATION_S guard not wired into the chat audio path (sibling of CVE-2026-5497)

n8nmedium

Insights API Missing Per-Project Authorization Exposes Workflow Names and Execution Stats Across Projects

GHSA-jmmj-93rg-6j39Fixed in 2.35.4Advisory
n8nmedium

Legacy Request Helper SSRF Check Validates uri While Axios Dispatches url

GHSA-jp9j-jr97-w9pjFixed in 2.33.4Advisory
n8nhigh

Strapi, SeaTable, and Mailcheck Nodes Leak Decrypted Credential Secrets into Persisted Execution Error Data

GHSA-vrv8-j27g-g7crFixed in 2.35.4Advisory
n8nhigh

Gmail and Brevo nodes accept non-string content, enabling local file read and SSRF

GHSA-95ph-833c-4wrpFixed in 2.35.4Advisory
n8nhigh

Expression Sandbox Escape via $fromAI Prototype Leak Leads to Host RCE

GHSA-9x83-43r8-5hwcFixed in 2.35.4Advisory
n8nhigh

Git Node Remote Code Execution via Incomplete Repository-Local Configuration Neutralization

GHSA-mwp5-2m32-r54hFixed in 2.35.4Advisory
n8nmedium

Query Injection in Elasticsearch and Google Cloud Firestore Nodes via Unescaped Expression Interpolation

GHSA-wxwj-8wv6-vpw2Fixed in 2.35.4Advisory
n8nhigh

Shared-Workflow Editor Can Exfiltrate Credentials via Workflow Tool Node Inline Sub-Workflow

GHSA-4r56-g65c-fm83Fixed in 2.35.4Advisory
n8nhigh

Expression Sandbox SpreadElement Bypass Enables Persistent Cross-Evaluation Native Object Mutation

GHSA-fg85-4wv2-p98jFixed in 2.35.4Advisory
Difyhigh

IDOR in AppMCPServer PUT Endpoint Allows Modification of Other Apps' MCP Servers

vLLMmedium

SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

Visual Studio Codehigh

TerminalInstance._createProcess() - Local RCE via extensions.json recommendation link

CVE-2026-58650Fixed in 1.132.1Advisory
Visual Studio Codehigh

Visual Studio Code web deployments - environmentService.ts - RCE via NODE_OPTIONS --import from URL payload

CVE-2026-69320Fixed in 1.132.1Advisory
Visual Studio Codehigh

TerminalInstance._createProcess - Workspace Trust bypass via terminal waitOnExit

CVE-2026-69278Fixed in 1.132.1Advisory
Visual Studio Codehigh

Copilot Custom Agent Hook Remote Code Execution Vulnerability

CVE-2026-70335Fixed in 1.132.1Advisory
Visual Studio Codehigh

Fileless RCE in VS Code Web Remote Terminal via URL-Controlled NODE_OPTIONS

CVE-2026-70336Fixed in 1.132.1Advisory
Kubernetesmedium

kubectl cp path traversal on Windows allows arbitrary file writes

CVE-2026-19444Advisory
Keycloakhigh

Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher

Keycloakhigh

Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation

Keycloakmedium

Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text

Keycloakhigh

Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction

Keycloakhigh

Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation

Keycloakmedium

Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary

Keycloakhigh

Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers

n8nmedium

SSRF Protection Bypass via SearXNG Tool Allows Member Users to Read Internal Service Responses

GHSA-9rp2-wm75-c5fjFixed in 2.33.4Advisory
n8nhigh

Code execution in the n8n Git node via unchecked repository-local git configuration

GHSA-m87g-qr43-ccvcFixed in 2.33.4Advisory
n8nmedium

ReDoS in Filter and Switch Node Regex Matching Allows Worker Denial of Service

GHSA-q3fv-295f-qfpfFixed in 2.33.4Advisory
n8nmedium

GraphQL Node Allowed-Domains Bypass Permits Restricted Credential Exfiltration

GHSA-wcv8-x773-j96rFixed in 2.33.4Advisory
n8nhigh

Custom-role deletion's reassignment path bypasses project-scoped authorization

GHSA-xhmh-8fgr-xqhjFixed in 2.33.4Advisory
n8nhigh

JavaScript Task Runner VM Sandbox Escape via EventEmitter Prototype Pollution Leads to Remote Code Execution

GHSA-m3hg-p5r9-fg9hFixed in 2.33.4Advisory
n8nhigh

GraphQL Node Raw Error Re-throw Leaks Decrypted Credential Headers into Persisted Execution Data

GHSA-9fqj-7wc5-cwhxFixed in 2.33.4Advisory
n8nhigh

Resource Locator Link Preview Expression Injection Allows Cross-User Script Execution

GHSA-fh4c-9rr2-p7qcFixed in 2.33.4Advisory
n8nmedium

MCP create_workflow_from_code Accepts Cross-Project Credentials When Auth Type Is an Expression

GHSA-vfrj-582q-mvcpFixed in 2.33.4Advisory
n8nhigh

Supabase Node PostgREST Filter Injection in Row Get Many, Delete, and Update Operations

GHSA-f4f3-2g67-4vhmFixed in 2.33.4Advisory
n8nhigh

MongoDB Node NoSQL Injection in Find, Delete, and Aggregate Operations via Unescaped Expression Interpolation

GHSA-953p-jm2c-8h5jFixed in 2.33.4Advisory
n8nlow

SSRF Protection Bypass via OAuth2 Credential Token Exchange Reflects Internal Response Body

GHSA-c4f6-59xq-95wwFixed in 2.33.4Advisory
n8nhigh

RCE in the n8n Main Process via Path Traversal in MCP Node-Schema Loading

GHSA-6h4x-896x-fw5mFixed in 2.33.4Advisory
Honomedium

`memo()` retains SSR output across requests, leading to cross-user data disclosure

Open WebUImedium

Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

vLLMlow

Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

vLLMmedium

Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

vLLMmedium

ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

vLLMmedium

Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

n8nmedium

PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances

GHSA-jqwr-vx3p-r266Fixed in 2.31.5Advisory
n8nhigh

Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`

n8nmedium

Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory

GHSA-pf2q-pxhf-hgmwFixed in 2.31.5Advisory
n8nhigh

Account Takeover via Unverified Email Claim in Token Exchange Embed Login

GHSA-8342-988q-86crFixed in 2.31.5Advisory
n8nhigh

Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes

GHSA-64xh-79j6-r5v8Fixed in 2.31.5Advisory
n8nhigh

Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction

GHSA-gf29-4f56-r2jfFixed in 2.31.5Advisory
n8nhigh

Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Code Execution

GHSA-hx4h-vr3m-45vhFixed in 2.31.5Advisory
n8nhigh

Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

GHSA-2x35-3fw4-9jr4Fixed in 2.31.5Advisory
n8nhigh

Expression sandbox escape via arrow-function bodies enabling command execution

GHSA-gv7g-jm28-cr3mFixed in 2.31.5Advisory
n8nhigh

Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON

GHSA-cj9h-qx8g-pq2gFixed in 2.31.5Advisory
n8nmedium

Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

GHSA-652q-gvq3-74qvFixed in 2.31.5Advisory
n8nhigh

Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service

GHSA-xwx6-jjhv-84p8Fixed in 2.35.4Advisory
Next.jsmedium

Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

Astrolow

Cross-site scripting via unescaped transition:* directive values on hydrated islands

CVE-2026-59727Fixed in 7.0.4Advisory
Astrolow

XSS via unescaped spread attribute names in custom element rendering

CVE-2026-59729Fixed in 7.0.5Advisory
Astrolow

composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered

CVE-2026-73423Fixed in 7.0.5Advisory
Astromedium

Unauthenticated path override in the @astrojs/vercel ISR function

CVE-2026-73424Fixed in 11.0.3Advisory
Astromedium

Reflected XSS via unescaped View Transition animation properties

CVE-2026-73422Fixed in 7.1.0Advisory
Astrolow

Backslash-prefixed paths not recognized as internal by trailing-slash redirect in @astrojs/node

CVE-2026-59730Fixed in 11.0.2Advisory
Astromedium

XML injection in @astrojs/rss via unescaped source and enclosure fields

CVE-2026-59728Fixed in 4.0.19Advisory
Astrolow

@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped

CVE-2026-73425Fixed in 8.1.2Advisory
n8nhigh

Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution