GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,272
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,521
Pub
12
RubyGems
1,007
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
12 advisories
Filter by severity
An improper neutralization of escape, meta, or control sequences vulnerability has been reported...
Moderate
Unreviewed
CVE-2025-62845
was published
Mar 20, 2026
Mailpit has an SMTP Header Injection via Regex Bypass
Moderate
CVE-2026-23829
was published
for
github.com/axllent/mailpit
(Go)
Jan 20, 2026
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server...
Moderate
Unreviewed
CVE-2025-65082
was published
Dec 5, 2025
Soft Serve does not sanitize ANSI escape sequences in user input
Moderate
CVE-2025-64494
was published
for
github.com/charmbracelet/soft-serve
(Go)
Nov 6, 2025
Active Record logging vulnerable to ANSI escape injection
Moderate
CVE-2025-55193
was published
for
activerecord
(RubyGems)
Aug 13, 2025
gurk (aka gurk-rs) mishandles ANSI escape sequences
Moderate
CVE-2025-30089
was published
for
gurk
(Rust)
Mar 17, 2025
MongoDB Shell may be susceptible to control character injection via pasting
Moderate
CVE-2025-1692
was published
for
mongosh
(npm)
Feb 27, 2025
jte's HTML templates containing Javascript template strings are subject to XSS
Moderate
CVE-2025-23026
was published
for
gg.jte:jte
(Maven)
Jan 13, 2025
python-sql SQL injection vulnerability
Moderate
CVE-2024-9774
was published
for
python-sql
(pip)
Dec 27, 2024
Jinja has a sandbox breakout through malicious filenames
Moderate
CVE-2024-56201
was published
for
jinja2
(pip)
Dec 23, 2024
Denial of service (DoS) when processing Git credentials
Moderate
CVE-2022-43756
was published
for
github.com/rancher/wrangler
(Go)
Jan 25, 2023
Control character injection in console output in github.com/ipfs/go-ipfs
Moderate
CVE-2020-26283
was published
for
github.com/ipfs/go-ipfs
(Go)
Jun 23, 2021
ProTip!
Advisories are also available from the
GraphQL API