GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
42
Go
3,114
Maven
5,000+
npm
5,000+
NuGet
826
pip
4,428
Pub
12
RubyGems
988
Rust
1,171
Swift
50
Unreviewed advisories
All unreviewed
5,000+
363 advisories
Filter by severity
org.eclipse.jetty:jetty-http has different parsing of invalid URIs
Low
CVE-2025-11143
was published
for
org.eclipse.jetty:jetty-http
(Maven)
Mar 5, 2026
Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
Low
CVE-2025-12150
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 27, 2026
Snowflake JDBC Driver is Vulnerable to Uncontrolled Resource Consumption through SdkProxyRoutePlanner
Low
CVE-2026-3293
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Feb 27, 2026
PSI Probe: Broken access control can lead to DoS
Low
CVE-2026-3269
was published
for
com.github.psi-probe:psi-probe-core
(Maven)
Feb 27, 2026
PSI Probe vulnerable to Server-Side Request Forgery
Low
CVE-2026-3270
was published
for
com.github.psi-probe:psi-probe-core
(Maven)
Feb 27, 2026
Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
Low
CVE-2026-2733
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 19, 2026
mingSoft MCMS does not properly restrict file uploads
Low
CVE-2026-2666
was published
for
net.mingsoft:ms-mcms
(Maven)
Feb 18, 2026
Apache Tomcat - Security constraint bypass with HTTP/0.9
Low
CVE-2026-24733
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Feb 17, 2026
Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability
Low
CVE-2026-23901
was published
for
org.apache.shiro:shiro-core
(Maven)
Feb 10, 2026
Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query log
Low
CVE-2026-1337
was published
for
org.neo4j:neo4j
(Maven)
Feb 6, 2026
Keycloak Server-Side Request Forgery (SSRF) vulnerability
Low
CVE-2026-1518
was published
for
org.keycloak:keycloak-parent
(Maven)
Feb 2, 2026
Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributes
Low
CVE-2025-13881
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 2, 2026
Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods
Low
CVE-2026-1190
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 26, 2026
Apache Karaf Decanter has Deserialization of Untrusted Data in its Log Socket Collector
Low
CVE-2026-24656
was published
for
org.apache.karaf.decanter.collector:org.apache.karaf.decanter.collector.log.socket
(Maven)
Jan 26, 2026
Logback allows an attacker to instantiate classes already present on the class path
Low
CVE-2026-1225
was published
for
ch.qos.logback:logback-core
(Maven)
Jan 22, 2026
Keycloak Admin REST API exposes backend schema and rules
Low
CVE-2025-14083
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 21, 2026
Keycloak does not validate and update refresh token usage atomically
Low
CVE-2026-1035
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 21, 2026
PlantUML is vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams
Low
CVE-2026-0858
was published
for
net.sourceforge.plantuml:plantuml
(Maven)
Jan 16, 2026
Keycloak has an improper input validation vulnerability
Low
CVE-2026-0976
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Jan 15, 2026
Jenkins has a CSRF vulnerability on the login form
Low
CVE-2025-67639
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Dec 10, 2025
Keycloak Admin REST (Representational State Transfer) API does not properly enforce permissions
Low
CVE-2025-14082
was published
for
org.keycloak:keycloak-services
(Maven)
Dec 10, 2025
Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
Low
CVE-2025-66453
was published
for
org.mozilla:rhino
(Maven)
Dec 3, 2025
Keycloak unable to restrict access to the admin console
Low
CVE-2025-10939
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Dec 2, 2025
NutzBoot vulnerable to information disclosure
Low
CVE-2025-13804
was published
for
org.nutz:nutzboot-parent
(Maven)
Dec 1, 2025
NutzBoot vulnerable to deserialization
Low
CVE-2025-13805
was published
for
org.nutz:nutzboot-parent
(Maven)
Dec 1, 2025
ProTip!
Advisories are also available from the
GraphQL API