GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
35,538 advisories
Filter by severity
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
Moderate
CVE-2026-86079
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
Moderate
CVE-2026-86078
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
Moderate
CVE-2026-86994
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
High
CVE-2026-86083
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
Moderate
CVE-2026-86077
was published
for
n8n
(npm)
Sep 10, 2026
Traefik: ForwardAuth identity spoofing via dot-form header alias
Moderate
CVE-2026-88011
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
Moderate
CVE-2026-88012
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements
High
CVE-2026-88060
was published
for
@angular/platform-server
(npm)
Sep 10, 2026
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR
High
CVE-2026-88056
was published
for
@angular/platform-server
(npm)
Sep 10, 2026
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
Moderate
CVE-2026-88059
was published
for
@angular/common
(npm)
Sep 10, 2026
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler
Moderate
CVE-2026-88057
was published
for
@angular/compiler
(npm)
Sep 10, 2026
Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration
High
CVE-2026-55416
was published
for
pimcore/pimcore
(Composer)
Sep 10, 2026
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
High
CVE-2026-86082
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
High
CVE-2026-86081
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
High
CVE-2026-86075
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
High
CVE-2026-86076
was published
for
n8n
(npm)
Sep 10, 2026
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
Moderate
CVE-2026-87017
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
Moderate
CVE-2026-87994
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
High
CVE-2026-87995
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
High
CVE-2026-87996
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
Moderate
CVE-2026-87997
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
High
CVE-2026-87998
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
High
CVE-2026-87999
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
Moderate
CVE-2026-88005
was published
for
open-webui
(pip)
Sep 10, 2026
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
High
CVE-2026-59161
was published
for
github.com/xuri/excelize
(Go)
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API