GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
41
Go
3,098
Maven
5,000+
npm
4,984
NuGet
826
pip
4,425
Pub
12
RubyGems
988
Rust
1,170
Swift
50
Unreviewed advisories
All unreviewed
5,000+
11,851 advisories
Filter by severity
Flowise Vulnerable to PII Disclosure on Unauthenticated Forgot Password Endpoint
Moderate
GHSA-jc5m-wrp2-qq38
was published
for
flowise
(npm)
Mar 5, 2026
Flowise has Insufficient Password Salt Rounds
Moderate
GHSA-x2g5-fvc2-gqvp
was published
for
flowise
(npm)
Mar 5, 2026
MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Injection and Email Forgery
Moderate
CVE-2026-30227
was published
for
MimeKit
(NuGet)
Mar 5, 2026
mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint
Moderate
CVE-2026-29787
was published
for
mcp-memory-service
(pip)
Mar 5, 2026
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
Moderate
CVE-2026-3419
was published
for
fastify
(npm)
Mar 5, 2026
OliveTin doesn't check view permission when returning dashboards
Moderate
CVE-2026-30233
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
EC-CUBE has a Vulnerability that Allows MFA Bypass in the Administrative Interface
Moderate
GHSA-7rhv-h82h-vpjh
was published
for
ec-cube/ec-cube
(Composer)
Mar 5, 2026
OliveTin has crash on NPE by calling APIs with invalid bindings or log references
Moderate
GHSA-fwhj-785h-43hh
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
OliveTin's RestartAction always runs actions as guest
Moderate
CVE-2026-30225
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
OliveTin Session Fixation: Logout Fails to Invalidate Server-Side Session
Moderate
CVE-2026-30224
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
stellar-xdr's StringM::from_str bypasses max length validation
Moderate
CVE-2026-29795
was published
for
stellar-xdr
(Rust)
Mar 5, 2026
Gokapi has CSRF in Login Endpoint
Moderate
CVE-2026-29084
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion
Moderate
CVE-2026-29061
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
LangGraph checkpoint loading has unsafe msgpack deserialization
Moderate
CVE-2026-28277
was published
for
langgraph
(pip)
Mar 5, 2026
Gogs: Access tokens get exposed through URL params in API requests
Moderate
CVE-2026-26196
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names
Moderate
CVE-2026-26195
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gokapi has privilege escalation with auth token
Moderate
CVE-2026-29060
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
Gokapi has Data Leak in Upload Status Stream
Moderate
CVE-2026-28682
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
Mercurius: Incorrect Content-Type parsing can lead to CSRF attack
Moderate
CVE-2025-64166
was published
for
mercurius
(npm)
Mar 5, 2026
Leantime has HTML injection through firstname and lastname fields
Moderate
GHSA-qrfh-cc86-vc8c
was published
for
leantime/leantime
(Composer)
Mar 5, 2026
Python-Markdown has an Uncaught Exception
Moderate
CVE-2025-69534
was published
for
Markdown
(pip)
Mar 5, 2026
django-allauth has an open redirect vulnerability
Moderate
CVE-2026-27982
was published
for
django-allauth
(pip)
Mar 5, 2026
Agentgateway is missing parameter sanitization in MCP to OpenAPI conversion
Moderate
CVE-2026-29791
was published
for
github.com/agentgateway/agentgateway
(Go)
Mar 5, 2026
eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write
Moderate
CVE-2026-29780
was published
for
eml-parser
(pip)
Mar 5, 2026
changedetection.io has Reflected XSS in its RSS Tag Error Response
Moderate
CVE-2026-29038
was published
for
changedetection.io
(pip)
Mar 4, 2026
ProTip!
Advisories are also available from the
GraphQL API