GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
257 advisories
Filter by severity
An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request...
High
Unreviewed
CVE-2022-45059
was published
Nov 9, 2022
h11 accepts some malformed Chunked-Encoding bodies
Critical
CVE-2025-43859
was published
for
h11
(pip)
Apr 24, 2025
CVE-2025-1386- Query smuggling in ch-go library
Moderate
CVE-2025-1386
was published
for
github.com/ClickHouse/ch-go
(Go)
Apr 12, 2025
croogo Host header injection
Moderate
CVE-2024-29643
was published
for
croogo/croogo
(Composer)
Apr 21, 2025
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct...
High
Unreviewed
CVE-2024-33452
was published
Apr 22, 2025
An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS...
High
Unreviewed
CVE-2017-15643
was published
May 17, 2022
The team has identified a critical vulnerability in the http server of the most recent version of...
Moderate
Unreviewed
CVE-2024-27982
was published
May 7, 2024
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This...
High
Unreviewed
CVE-2024-53868
was published
Apr 3, 2025
golang.org/x/net/http2/h2c vulnerable to request smuggling attack
High
CVE-2022-41721
was published
for
golang.org/x/net
(Go)
Jan 14, 2023
Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via...
Moderate
Unreviewed
CVE-2025-30346
was published
Mar 21, 2025
Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers
High
CVE-2025-31137
was published
for
@react-router/express
(npm)
Apr 1, 2025
IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack...
Moderate
Unreviewed
CVE-2022-39163
was published
Mar 26, 2025
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack...
Moderate
Unreviewed
CVE-2024-27185
was published
Aug 20, 2024
Gunicorn HTTP Request/Response Smuggling vulnerability
High
CVE-2024-6827
was published
for
gunicorn
(pip)
Mar 20, 2025
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are...
Critical
Unreviewed
CVE-2023-25725
was published
Feb 14, 2023
HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers...
High
Unreviewed
CVE-2024-10264
was published
Mar 20, 2025
In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the...
Moderate
Unreviewed
CVE-2024-56908
was published
Feb 14, 2025
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
Moderate
Unreviewed
CVE-2025-29904
was published
Mar 12, 2025
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in...
Critical
Unreviewed
CVE-2025-1867
was published
Mar 3, 2025
A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to...
Moderate
Unreviewed
CVE-2023-51219
was published
Jun 3, 2024
X-Forwarded-For header allows brute-forcing autoblocked IP addresses
Critical
CVE-2023-29141
was published
for
mediawiki/core
(Composer)
Mar 31, 2023
Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows...
High
Unreviewed
CVE-2024-23452
was published
Feb 8, 2024
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services...
Moderate
Unreviewed
CVE-2024-21281
was published
Oct 15, 2024
Undertow incorrectly parses cookies
High
CVE-2023-4639
was published
for
io.undertow:undertow-core
(Maven)
Nov 17, 2024
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access...
Moderate
Unreviewed
CVE-2025-0752
was published
Jan 28, 2025
ProTip!
Advisories are also available from the
GraphQL API