2026 CVE Vulnerabilities

50,996 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-67334MEDIUM5.1better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endp...
CVE-2026-67333HIGH7.2better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redi...
CVE-2026-67332MEDIUM6.4@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing...
CVE-2026-67331HIGH8.7better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator b...
CVE-2026-67330CRITICAL9.9@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7....
CVE-2026-67329HIGH7.1@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization b...
CVE-2026-67328HIGH8.6@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling ...
CVE-2026-67327HIGH8.7better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable...
CVE-2026-67326HIGH7.3GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attac...
CVE-2026-67325HIGH8.8GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option p...
CVE-2026-67324CRITICAL9.8GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>...
CVE-2026-67323HIGH8.6GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and g...
CVE-2026-67322HIGH8.7GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied rem...
CVE-2026-67321MEDIUM6.9axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js w...
CVE-2026-67320HIGH8.3axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hard...
CVE-2026-67319MEDIUM6.3axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the...
CVE-2026-67318MEDIUM6.3axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bo...
CVE-2026-67317MEDIUM6.3axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch a...
CVE-2026-67316MEDIUM6.3axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype h...
CVE-2026-67315MEDIUM6.9axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBy...
CVE-2026-67314MEDIUM6.3axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/a...
CVE-2026-67313MEDIUM6.3axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names wi...
CVE-2026-67312MEDIUM6.3axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (...
CVE-2026-67311HIGH8.2Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fail...
CVE-2026-67310MEDIUM5.4OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now