GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,607 advisories
Filter by severity
Fleet: ORDER BY column injection on activity list endpoints
Low
GHSA-rxhg-vcww-2mpw
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 20, 2026
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
Low
GHSA-22w5-2fxg-vrwx
was published
for
github.com/opentofu/opentofu
(Go)
Aug 20, 2026
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
Low
GHSA-h58c-xccx-75m3
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Low
GHSA-8fxq-53rx-ph5f
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
BuildKit has a possible runtime DoS via unbounded group parsing
Low
CVE-2026-61712
was published
for
github.com/moby/buildkit
(Go)
Aug 19, 2026
MobSF has SSRF port restriction bypass in assetlinks_check
Low
CVE-2026-68927
was published
for
mobsf
(pip)
Aug 18, 2026
MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
Low
CVE-2026-63641
was published
for
magicmirror
(npm)
Aug 18, 2026
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
Low
CVE-2026-61634
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
Low
CVE-2026-71849
was published
for
hono
(npm)
Aug 7, 2026
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Low
CVE-2026-71847
was published
for
json
(RubyGems)
Aug 7, 2026
Craft CMS: Incorrect path validation could potentially lead to path traversal
Low
CVE-2026-72783
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Mermaid configuration APIs allow prototype pollution
Low
CVE-2026-71438
was published
for
mermaid
(npm)
Aug 6, 2026
Contao: Possible path traversal in job download URIs
Low
CVE-2026-55825
was published
for
contao/contao
(Composer)
Aug 6, 2026
Contao crawler leaks auth credentials to external hosts
Low
CVE-2026-55824
was published
for
contao/contao
(Composer)
Aug 6, 2026
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Low
CVE-2026-71326
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
Low
GHSA-945v-v9p3-v5xw
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
Low
GHSA-gwfq-86j8-7qhv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
Electron: Cross-origin iframe can position native autofill popup
Low
CVE-2026-70600
was published
for
electron
(npm)
Aug 5, 2026
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
Low
CVE-2026-70598
was published
for
electron
(npm)
Aug 5, 2026
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Low
CVE-2026-70483
was published
for
open-webui
(pip)
Aug 4, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
Low
CVE-2026-54787
was published
for
github.com/sigstore/sigstore-go
(Go)
Jul 31, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Low
CVE-2026-53607
was published
for
apostrophe
(npm)
Jul 31, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
CVE-2026-54522
was published
for
msgpack
(RubyGems)
Jul 30, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
GHSA-pmwx-rm49-xv39
was published
for
activerecord-tenanted
(RubyGems)
Jul 29, 2026
ProTip!
Advisories are also available from the
GraphQL API