GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,744
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
35,552 advisories
Filter by severity
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
High
CVE-2026-87996
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
Moderate
CVE-2026-87997
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
High
CVE-2026-87998
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
High
CVE-2026-87999
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
Moderate
CVE-2026-88005
was published
for
open-webui
(pip)
Sep 10, 2026
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
High
CVE-2026-59161
was published
for
github.com/xuri/excelize
(Go)
Sep 10, 2026
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
Moderate
CVE-2026-59162
was published
for
github.com/xuri/excelize
(Go)
Sep 10, 2026
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
High
GHSA-x7m8-jrm8-hpvx
was published
for
@eigenpal/docx-editor-core
(npm)
Sep 10, 2026
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
Moderate
CVE-2026-88000
was published
for
open-webui
(pip)
Sep 9, 2026
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Moderate
CVE-2026-88001
was published
for
open-webui
(pip)
Sep 9, 2026
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
Moderate
CVE-2026-88002
was published
for
open-webui
(pip)
Sep 9, 2026
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
High
CVE-2026-59185
was published
for
github.com/identrail/identrail
(Go)
Sep 9, 2026
@openhop/server: Path Traversal in Flow ID File Operations
High
CVE-2026-59179
was published
for
@openhop/server
(npm)
Sep 9, 2026
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
High
CVE-2026-59177
was published
for
esphome-device-builder
(pip)
Sep 9, 2026
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
High
CVE-2026-59176
was published
for
functype-mcp-server
(npm)
Sep 9, 2026
Joker linter executed project-local .jokerd/linter.* files during linting
High
CVE-2026-59172
was published
for
github.com/candid82/joker
(Go)
Sep 9, 2026
Komari: Management Interface CSRF
High
GHSA-hxjg-93wc-h8p8
was published
for
github.com/komari-monitor/komari
(Go)
Sep 9, 2026
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
High
CVE-2026-59160
was published
for
@yeger/turbo-graph
(npm)
Sep 9, 2026
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
High
CVE-2026-59158
was published
for
nuxt-ollama
(npm)
Sep 9, 2026
webhookd: Unrestricted HTTP Header to Shell Variable Injection
Moderate
CVE-2026-59157
was published
for
github.com/ncarlier/webhookd
(Go)
Sep 9, 2026
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
High
CVE-2026-55864
was published
for
org.geonetwork-opensource:gn-web-app
(Maven)
Sep 9, 2026
smol-toml: Denial of Service via malformed TOML documents
High
CVE-2026-85730
was published
for
smol-toml
(npm)
Sep 9, 2026
weasyprint Has Server-Side Request Forgery (SSRF)
Moderate
CVE-2026-55073
was published
for
weasyprint
(pip)
Sep 9, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
Moderate
CVE-2026-54529
was published
for
sqladmin
(pip)
Sep 9, 2026
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
Moderate
CVE-2026-53495
was published
for
github.com/containerd/containerd
(Go)
Sep 9, 2026
ProTip!
Advisories are also available from the
GraphQL API