Security advisories
The newest 300 of 1222 advisories the tracked projects have published, with the release that carries the fix. Severity is the one its publisher assigned. Nothing here is our judgement. Each product keeps its own full register, linked below.
- Advisories
- 1222 across 42 products
- critical
- 61
- high
- 457
- medium
- 549
- low
- 88
- Newest
- 9 Oct 2026 2 days ago
An advisory is listed only when its publisher has published it with an identifier. Release notes that use the word security without one are not listed here, because a security page is worth reading only if every line on it can be checked. 1027 of these carry a CVE, and 619 are matched to the release in the archive that fixed them.
This page is a copy of what the publishers published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Every product’s own register
1222 advisories, all of themNewest 300 across every product
Unvalidated stop_token_ids causes engine crash (DoS) and out-of-bounds GPU write
Remote DoS in vLLM via allowed_token_ids Speculative-Decoding Metadata Mismatch
Cross-tenant DoS via uninitialized LogprobsTensors with prompt_logprobs
Frame-count cap bypass in VideoMediaIO.load_base64 for video/jpeg via media_io_kwargs.video.num_frames
Remote DoS in disaggregated multimodal /inference/v1/generate via malicious kwargs_data / mm_placeholders
Nemotron-VL processors disable Pillow decompression-bomb guard globally, enabling unauthenticated DoS
SSRF via X-Request-Id header drives P2pNcclConnector outbound ZMQ+NCCL pair, leaking KV-cache tensors
Multimodal chat audio decoding bypasses the decompression-bomb duration limit
Rust gRPC Generate accepts out-of-vocabulary prompt token IDs and can terminate EngineCore
Rust gRPC output_candidates.token_ids bypasses logprob_token_ids limits and can terminate EngineCore
Rust gRPC CandidateTokens.top_n bypasses max_logprobs and can terminate EngineCore
Cross origin script execution through Vite custom middleware
First 4 bytes of files outside of `server.fs` setting is exposed by `?vite-wasm-instance`
Files outside `server.fs.allow` could be served when project paths match system paths on non-Windows machine
DoS via unvalidated mm_processor_kwargs in multimodal image processors (Isaac, InternVL, H2OVL, etc.)
Caller-controllable values become or collide with shared cache keys, enabling cross-request cache aliasing (2 sites: multimodal EXIF hash and prefix-cache extra keys)
Request-controlled mm_processor_kwargs.code_revision allows remote code execution
MOSS-Audio request-controlled processor cache permits remote memory exhaustion
An oversized min_tokens in one request hangs the vLLM engine while /health stays green
Forged multimodal UUID + P0/P1 processor-cache eviction drift: unauthenticated remote crash of the whole vLLM engine
V1 InputBatch.condense leaves a stale allowed_token_ids mask on recycled batch rows
Read-only API key and JWTs accepted on internal gRPC API when enforce_internal_auth is enabled
Blind VXLAN injection into encrypted overlay networks from cluster peer
Docker Engine insecure-registry fallback via malicious DNS responses
Execute Sub-workflow Inline JSON Allows Member to Spoof Workflow Identity for Credential Authorization, Static Data, and Error-Workflow Dispatch
Unauthenticated Cross-Project Workflow Execution via Webhook Path-Only Resolution
Cross-Project Agent Ownership Transfer via Client-Supplied Agent ID
Shared-Workflow Credential Check Misses Agent Node Parameter Credentials
Stored XSS via Same-Origin Blob URL in the Binary-Data File Preview
Prototype Pollution in the AI Workflow Builder Connection Merge
n8n Chat Trigger Stored XSS via customCss Parameter on Hosted-Chat Page
Send-and-Wait HMAC Bypass Allows Unauthenticated Approval of Waiting Executions
Code Execution in the Git Node Log Operation via Unneutralized Repository Configuration
Shared-Workflow Credential Check Misses Nested and Tool Inline Sub-Workflows
Unauthenticated Unbounded OAuth Client Persistence via the Authorize Endpoint
Shared Prototype Mutation Through the MCP Workflow-Validation Interpreter Allows Owner Account Takeover
Cross-User Agent Chat Resume Allows Hijacking Another User's Pending Tool Approval
SQL Injection in the Microsoft SQL Node via Expression Interpolation into the Query Field
Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass
Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitution and persistent denial of service
Cache poisoning of SSG and ISR pages in self-hosted Next.js applications
Information disclosure in the Next.js development server's Model Context Protocol endpoint
Server-Side Request Forgery in Image Optimization
Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages
Cache leak across root param values in nested 'use cache' functions
`serveStatic` decodes the request path a second time, leading to bypass of middleware on static paths
Terminal users can manage Terminals policies and other users' terminals via the terminal proxy
Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle
Crafted IAMF audio upload reaches a PyAV/FFmpeg native heap overflow through the speech transcription path — denial of service
Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core
Stored XSS via user-authored tool-call embeds in the Markdown renderer
Instance-wide stall via recurrence rules with no possible occurrence
Any authenticated user can exhaust worker memory via a nested-repetition knowledge-search pattern
Instance-wide stall via automation recurrence rules that evade sub-daily frequency detection
Any authenticated user can reach disabled model provider backends via an explicit backend index
Any authenticated user can repeatedly stall a worker via file-search regex on the event loop
Any authenticated user can exhaust server memory via a compressed remote image in a chat message
Tool source code disclosed to read-only users via the tool export endpoint
Other users' session tokens disclosed via OAuth-mode connections, tool servers and terminals
Viewer session token theft via a script link in a shared chat's citation
Any authenticated user can steal another user's session token via script embedded in a DOCX preview
Deactivated users keep terminal command execution via an already open terminal WebSocket
Viewer session token theft via javascript: URLs in chat message links
Directory structure of inaccessible knowledge bases disclosed via an unscoped directory id
Any website can steal a signed-in user's session token via the community stats message handler
Knowledge base collaborators keep read and delete access to removed files via stale file metadata
Read-only shared folder members can still add chats to the folder by forking
Revoked users keep signing in via token exchange when roles are only in the ID token
Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`
Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service
Scale-out disaggregated multimodal transport trusts caller-supplied features — shared EngineCore denial of service, encoder-cache poisoning, and transport integrity loss (5 sites)
Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites)
GLMGA video sampling permits request-driven CPU and memory exhaustion
Unbounded Prometheus label cardinality from attacker-controlled HTTP method tokens in the vLLM Rust frontend metrics middleware (unauthenticated denial of service)
Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach
Remote Code Execution in next/og ImageResponse
Approval Bypass in the Send and Wait Node's Approve Within Chat Mode
Dynamic Credentials Authorize Endpoint Leaks Session Token to Attacker-Controlled Resolver
Unescaped Parameter Interpolation into Third-Party Query Languages Enables Filter Bypass and Bulk Data Disclosure
Path Traversal in the n8n Node Redirects Public API Calls to Unintended Resources
Wekan and Baserow Credentials Leak Account Password to Unvalidated Host via preAuthentication Hook
Path Traversal and Query Injection via the Supabase Node Table Name
Path Traversal in Signed Resume URL Generation Enables Cross-Project Approval Forgery
SQL Injection in Oracle Database Node Delete Table Drop Operation
Credential Test Endpoint Resolves Project-Scoped Variables from Attacker-Controlled Project ID
Community Package Install Validation Bypass via PubSub in Queue Mode Deployments
NoSQL Injection in MongoDB Chat Memory Node Allows Unauthenticated Cross-Session Chat History Disclosure
Stored DOM XSS via Resource Locator Dropdown Link Handling
Supabase Node Filters (String) Mode Allows PostgREST Filter Injection
Duplicate Node IDs Bypass Workflow Credential Tamper Guard, Exposing Credentials to a Shared Workflow Editor
Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Check
Missing Webhook Signature Verification in Webflow Trigger Node Allows Forged Event Injection
Replay protection bypass leads to unauthorized access via database driver semantics mismatch
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
Unbounded memory growth in the NestJS TCP microservice transport
Path-scoped middleware bypass via absolute-form request targets
Remote process termination via a deeply nested microservice message pattern
StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation
Subpath symlinking on Windows nodes permits NTLM coercion
Out-of-range `stop_token_ids` with `min_tokens` can kill vLLM EngineCore
Incomplete artifact pin propagation in FunAudioChat and Tarsier2
Rust HTTP/gRPC stop_token_ids bypass Python vocab-bound fix and can terminate EngineCore
Disaggregated generate skips decoder prompt-length validation for some multimodal processors
Remote media is fetched and fully materialized before the documented media size / item limits are enforced — remote pre-inference memory and bandwidth exhaustion (4 sites)
Sampler Subclass Counter Shadowing Bypasses PyNvVideoCodec Decoder Limits and GPU Memory Accounting
Uncontrolled resource consumption: multimodal chat audio decoding ignores `VLLM_MAX_AUDIO_CLIP_FILESIZE_MB`
vLLM DoS via unbounded `cache_salt` length: multi-hundred-MB salt stalls the single EngineCore scheduler thread (CPU exhaustion)
XSS in Debug Page Information
Users denied by the OAuth role policy can still sign in via token exchange
Trusted URL Validation Security Feature Bypass
Visual Studio Code Restricted Mode bypass via nested configuration objects
Visual Studio Code Workspace Trust bypass through attacker-controlled services
Agent Network Filter Bypass Vulnerability
Remote code execution through workspace-configured remote agent host connections
Visual Studio Code webview resource path containment bypass
Azure DevOps access token disclosure through GitHub Copilot Chat workspace settings
Information Disclosure through Automatic Remote Image Fetch in Chat
Visual Studio Code MCP gallery metadata path traversal
Agent Network Filter Security Feature Bypass
Agent Network Filter Security Feature Bypass
Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
Admin demoted through SSO role sync keeps read and write access to all users' notes
Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
A user's session cookies are sent to tool servers configured for bearer authentication
Any authenticated user can start a non-terminating request via a folder parent cycle
Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
hono/jsx renders plain strings unescaped in boundary components, leading to XSS
fastify vulnerable to request body replacement via an async validation result collision
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
fastify vulnerable to request validation bypass via skipped boolean false schemas
fastify vulnerable to header validation bypass via incomplete schema case normalization
Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
Denial of service: a negative token id in `/v1/embeddings` or `/pooling` input kills the vLLM engine via a CUDA device-side assertion
Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
Improper Authorization in Source Control Push Allows Cross-Project Workflow and Credential Deletion
Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
Git Node File Sandbox Escape via Relative Remote URL Base-Directory Mismatch
SSRF into internal services via DNS rebinding in the Playwright web loader
Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
Channel members can overwrite another member's message via the chat completions endpoint
Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
XSS in @vue/server-renderer via missing CR in attribute-name blacklist
Unauthenticated use-after-free of the Lua interpreter state in Valkey (script debugger command cache)
Use-after-free in the RDMA pending-data handler when a client
Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
Any authenticated user can inject chats into another user's folder via chat completions
Any authenticated user can reach the Azure platform channel via server-side web fetch
Users outside the OAuth domain allowlist can still sign in via token exchange
Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Any authenticated user can hang the server via a cyclic chat message history
Any authenticated user can hang the server via message deletion in a cyclic chat tree
Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Speech-to-text audio decode duration limit bypass via forged header sample rate
Denial of Service NanoNemoTronVL Video Audio Extraction Bomb
LlavaOnevision2 processor loader executes attacker model code with `trust_remote_code=False` (inert `trust_remote_code` kwarg to `transformers.get_class_from_dynamic_module`) — RCE from a malicious model
Malformed port in the Host header can crash the Node adapter
Authorization bypass from missing path-segment boundary check when stripping the configured base
Netlify Image CDN allowlist bypass enables SSRF
Remote code execution through AVIF image optimization
Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
Unauthenticated Remote Code Execution on windows-hosted servers
Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Unauthenticated audio decompression-bomb DoS in /v1/chat/completions: VLLM_MAX_AUDIO_DECODE_DURATION_S guard not wired into the chat audio path (sibling of CVE-2026-5497)
Insights API Missing Per-Project Authorization Exposes Workflow Names and Execution Stats Across Projects
Legacy Request Helper SSRF Check Validates uri While Axios Dispatches url
Strapi, SeaTable, and Mailcheck Nodes Leak Decrypted Credential Secrets into Persisted Execution Error Data
Gmail and Brevo nodes accept non-string content, enabling local file read and SSRF
Expression Sandbox Escape via $fromAI Prototype Leak Leads to Host RCE
Git Node Remote Code Execution via Incomplete Repository-Local Configuration Neutralization
Query Injection in Elasticsearch and Google Cloud Firestore Nodes via Unescaped Expression Interpolation
Shared-Workflow Editor Can Exfiltrate Credentials via Workflow Tool Node Inline Sub-Workflow
Expression Sandbox SpreadElement Bypass Enables Persistent Cross-Evaluation Native Object Mutation
IDOR in AppMCPServer PUT Endpoint Allows Modification of Other Apps' MCP Servers
Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
Agent network filter bypass via IPv4-mapped IPv6 literals
Fetch Web Page OS protocol handler remote code execution
TerminalInstance._createProcess() - Local RCE via extensions.json recommendation link
Visual Studio Code web deployments - environmentService.ts - RCE via NODE_OPTIONS --import from URL payload
TerminalInstance._createProcess - Workspace Trust bypass via terminal waitOnExit
Copilot Custom Agent Hook Remote Code Execution Vulnerability
Fileless RCE in VS Code Web Remote Terminal via URL-Controlled NODE_OPTIONS
Information disclosure vulnerability
Copilot Chat Security Feature Bypass Vulnerability
Cross-User Data Leak Vulnerability
vLLM Unauthenticated Requests Exploit DeepStream Backend Confusion for DoS
kubectl cp path traversal on Windows allows arbitrary file writes
Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher
Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation
Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text
Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction
Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation
Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary
Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
SSRF Protection Bypass via SearXNG Tool Allows Member Users to Read Internal Service Responses
Code execution in the n8n Git node via unchecked repository-local git configuration
Sandbox Escape in JavaScript Code Node via Prototype Pollution
ReDoS in Filter and Switch Node Regex Matching Allows Worker Denial of Service
GraphQL Node Allowed-Domains Bypass Permits Restricted Credential Exfiltration
Snowflake Node Arbitrary File Read and Write via Client-Side Commands
Custom-role deletion's reassignment path bypasses project-scoped authorization
JavaScript Task Runner VM Sandbox Escape via EventEmitter Prototype Pollution Leads to Remote Code Execution
GraphQL Node Raw Error Re-throw Leaks Decrypted Credential Headers into Persisted Execution Data
Resource Locator Link Preview Expression Injection Allows Cross-User Script Execution
Edit Image Node Injection Enables Blind SSRF
MCP create_workflow_from_code Accepts Cross-Project Credentials When Auth Type Is an Expression
Form Node Completion Page Sandbox CSP Bypass Leads to Stored XSS
Supabase Node PostgREST Filter Injection in Row Get Many, Delete, and Update Operations
MongoDB Node NoSQL Injection in Find, Delete, and Aggregate Operations via Unescaped Expression Interpolation
SSRF Protection Bypass via OAuth2 Credential Token Exchange Reflects Internal Response Body
RCE in the n8n Main Process via Path Traversal in MCP Node-Schema Loading
ReDoS in CORS middleware via Access-Control-Request-Headers
Algorithmic Complexity DoS in Language Middleware
Proxy Helper does not remove response headers listed in the `Connection` header
`memo()` retains SSR output across requests, leading to cross-user data disclosure
Any authenticated user can reach internal services via DNS rebinding on server-side URL fetches
Cross-user file content disclosure via request-scoped direct model knowledge metadata
Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Users denied the image-generation permission can still generate images via chat completions
Stored XSS via unescaped KaTeX render-error fallback in rendered messages
Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
Tool source code disclosed to read-only users via the tool list and get endpoints
Any authenticated user can cancel another user's chat generation via the chat delete endpoint
A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
Any member with write access to a standard channel can edit or delete other members' messages
Instance-wide stall via automation recurrence rules that force multi-second parsing
Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Account takeover via OAuth token exchange accepting tokens issued to any client
Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
Completion prompt lists fan out into unbounded engine requests
Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
Account Takeover via Unverified Email Claim in Token Exchange Embed Login
Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Code Execution
SSRF Protection Bypass via MCP Client Node
Authenticated code execution in the n8n Git node
Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
Expression sandbox escape via arrow-function bodies enabling command execution
Cross-Tenant Module-Cache Poisoning in the JS Task Runner
Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
Edit Image Node Format Injection Allows Arbitrary File Write
Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
UAF in Valkey with TLS may lead to remote code execution
UAF in stream deserialization may lead to remote code execution
Unauthenticated disclosure of internal Server Function endpoints
Denial of Service in the Image Optimization API using SVGs
Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Denial of Service in App Router using Server Actions
Middleware / Proxy bypass in App Router applications using Turbopack and single locale
Cache confusion of response bodies for requests with bodies
Server-Side Request Forgery in Server Actions on custom servers
Unbounded Server Action payload in Edge runtime
Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
Denial of Service in Server Functions
Cross-site scripting via unescaped transition:* directive values on hydrated islands
XSS via unescaped spread attribute names in custom element rendering
composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
Unauthenticated path override in the @astrojs/vercel ISR function
Reflected XSS via unescaped View Transition animation properties
Unhandled panic in worker goroutines
Backslash-prefixed paths not recognized as internal by trailing-slash redirect in @astrojs/node
XML injection in @astrojs/rss via unescaped source and enclosure fields
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
Cross-Tenant External API Detail Disclosure
Cross-Tenant External API Usage Enumeration
Cross-Tenant File Preview via Unscoped Console `file_id`
Remote Code Execution Vulnerability
Workspace Trust Security Feature Bypass Vulnerability
Secret exfiltration vulnerability
Google Service Account Private Key Exposed in JWT Header
Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution