GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,606 advisories
Filter by severity
rclone: http backend forwards custom/auth headers to a different host on redirect
Low
CVE-2026-88013
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
Low
CVE-2025-24978
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Sep 9, 2026
multer vulnerable to file size limit bypass via async fileFilter race condition
Low
CVE-2026-77063
was published
for
multer
(npm)
Sep 8, 2026
joi: Prototype pollution via a `__proto__` language key in custom messages
Low
CVE-2026-84368
was published
for
@hapi/joi
(npm)
Sep 8, 2026
joi: object().rename() with a template target can set the validated object's prototype
Low
CVE-2026-84367
was published
for
joi
(npm)
Sep 8, 2026
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
Low
CVE-2026-73087
was published
for
github.com/amir20/dozzle
(Go)
Sep 8, 2026
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
Low
GHSA-6hxq-p678-4hr2
was published
for
@simplewebauthn/server
(npm)
Sep 4, 2026
CKAN MCP Server: Information disclosure via verbose error reflection
Low
CVE-2026-73844
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 3, 2026
ImageMagick: Memory Leak when providing invalid options to the cli
Low
GHSA-cvhv-g4rq-3hmw
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Sep 2, 2026
Filament: Password validity disclosure for accounts denied panel access on login page
Low
CVE-2026-84307
was published
for
filament/filament
(Composer)
Sep 1, 2026
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
Low
GHSA-wwv5-g3v4-889x
was published
for
tornado
(pip)
Sep 1, 2026
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
Low
CVE-2026-55785
was published
for
github.com/free5gc/ausf
(Go)
Aug 28, 2026
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI
Low
CVE-2026-55891
was published
for
privatebin/privatebin
(Composer)
Aug 28, 2026
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
Low
CVE-2026-55588
was published
for
oras.land/oras
(Go)
Aug 28, 2026
Snipe-IT has a path traversal vulnerability via CSV import `image` field
Low
CVE-2026-55469
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
Low
CVE-2026-42350
was published
for
github.com/akuity/kargo
(Go)
Aug 27, 2026
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions
Low
CVE-2026-54713
was published
for
cakephp/queue
(Composer)
Aug 27, 2026
OpenSTAManager has HTML Injection in modules/utenti/edit.php
Low
CVE-2026-44701
was published
for
devcode-it/openstamanager
(Composer)
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
CVE-2026-54786
was published
for
wasmtime-wasi
(Rust)
Aug 26, 2026
kas Persistently Disables SSH Host Key Checking
Low
CVE-2026-54548
was published
for
kas
(pip)
Aug 26, 2026
netfoil vulnerable to improper handling of untrusted DoH response data
Low
GHSA-4ph6-mjv7-3fq6
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Aug 24, 2026
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure
Low
CVE-2026-71514
was published
for
nltk
(pip)
Aug 22, 2026
Wagtail: Identification of documents by SHA1 hash
Low
GHSA-92hv-j533-69wc
was published
for
wagtail
(pip)
Aug 20, 2026
Winter: Stored XSS through Backend List widget image columns
Low
GHSA-7mpf-4465-7fc2
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Fleet: ORDER BY column injection on activity list endpoints
Low
GHSA-rxhg-vcww-2mpw
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API