GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
105 advisories
Filter by severity
openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file...
Critical
Unreviewed
CVE-2026-81696
was published
Aug 27, 2026
openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted...
Critical
Unreviewed
CVE-2026-81694
was published
Aug 27, 2026
openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to...
Critical
Unreviewed
CVE-2026-81695
was published
Aug 27, 2026
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
High
CVE-2026-54511
was published
for
@logtape/syslog
(npm)
Aug 26, 2026
netfoil vulnerable to improper handling of untrusted DoH response data
Low
GHSA-4ph6-mjv7-3fq6
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Aug 24, 2026
openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs...
Critical
Unreviewed
CVE-2026-74885
was published
Aug 17, 2026
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary...
High
Unreviewed
CVE-2026-17481
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary...
Moderate
Unreviewed
CVE-2026-18148
was published
Aug 12, 2026
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
High
GHSA-7cx2-g3h9-382p
was published
for
crawl4ai
(pip)
Jun 16, 2026
Keycloak vulnerable to log Injection during WebAuthn authentication or registration
Moderate
CVE-2023-6484
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 17, 2024
morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
Moderate
CVE-2026-5078
was published
for
morgan
(npm)
Jul 10, 2026
netfoil: Attacker controlled data written to logs
Low
GHSA-7856-g3gv-9wq8
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Jul 7, 2026
Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant...
High
Unreviewed
CVE-2026-10745
was published
Jun 24, 2026
In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an...
Moderate
Unreviewed
CVE-2026-20260
was published
Jun 10, 2026
OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
Moderate
CVE-2026-45679
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-9016
was published
Jun 6, 2026
flask-cors vulnerable to log injection when the log level is set to debug
Moderate
CVE-2024-1681
was published
for
flask-cors
(pip)
Apr 19, 2024
A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log...
Moderate
Unreviewed
CVE-2026-6494
was published
Apr 17, 2026
Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
Moderate
CVE-2026-34478
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Apr 10, 2026
Keycloak logs sensitive headers
Moderate
CVE-2025-11537
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Feb 10, 2026
IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an...
Moderate
Unreviewed
CVE-2025-14684
was published
Mar 26, 2026
In Splunk IT Service Intelligence (ITSI) versions below 4.13.3 or 4.15.3, a malicious actor can...
High
Unreviewed
CVE-2023-4571
was published
Aug 30, 2023
Ansible-core information disclosure flaw
Moderate
CVE-2024-0690
was published
for
ansible-core
(pip)
Feb 6, 2024
OliveTin's email argument makes compliance harder, enables log injection
Moderate
GHSA-xx6g-43w2-9g6g
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 12, 2026
2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters...
Moderate
Unreviewed
CVE-2025-59784
was published
Mar 4, 2026
ProTip!
Advisories are also available from the
GraphQL API