GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
55
GitHub Actions
50
Go
3,722
Maven
5,000+
npm
5,000+
NuGet
935
pip
4,946
Pub
13
RubyGems
1,055
Rust
1,338
Swift
54
Unreviewed advisories
All unreviewed
5,000+
123 advisories
Filter by severity
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information
High
CVE-2026-42459
was published
for
github.com/free5gc/udm
(Go)
May 7, 2026
Flight vulnerable to sensitive information disclosure via default error handler
High
CVE-2026-42552
was published
for
flightphp/core
(Composer)
May 6, 2026
PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI
Moderate
CVE-2026-44226
was published
for
pyload-ng
(pip)
May 6, 2026
AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the Configured Clone Server
High
CVE-2026-43873
was published
for
wwbn/avideo
(Composer)
May 5, 2026
Spring gRPC AuthenticationException messages are reflected to remote client
Low
CVE-2026-40969
was published
for
org.springframework.grpc:spring-grpc
(Maven)
Apr 28, 2026
monetr: Server-side request forgery in Lunch Flow link creation and refresh
High
CVE-2026-41644
was published
for
github.com/monetr/monetr
(Go)
Apr 22, 2026
Meridian: Multiple defense-in-depth gaps (collection/depth caps, telemetry, retry, fan-out)
High
GHSA-f5v8-v6q3-q4h6
was published
for
Meridian.Mapping
(NuGet)
Apr 16, 2026
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication
High
CVE-2026-40245
was published
for
github.com/free5gc/udr
(Go)
Apr 14, 2026
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
High
CVE-2026-29146
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 9, 2026
Authorizer: CQL/N1QL Injection in Cassandra and Couchbase Backends via fmt.Sprintf String Interpolation
High
GHSA-jfwg-rxf3-p7r9
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`
Moderate
CVE-2026-28786
was published
for
open-webui
(pip)
Mar 27, 2026
Keycloak's identity-first login flow exposes user information
Low
CVE-2026-4633
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 23, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques
High
CVE-2026-33192
was published
for
github.com/free5gc/udm
(Go)
Mar 18, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request
Moderate
CVE-2026-33065
was published
for
github.com/free5gc/udm
(Go)
Mar 18, 2026
parse-server: Malformed `$regex` query leaks database error details in API response
Moderate
CVE-2026-30835
was published
for
parse-server
(npm)
Mar 6, 2026
Curio exposes database credentials to users with network access through verbose HTTP error responses
High
GHSA-gj6x-q8rh-wj6x
was published
for
github.com/filecoin-project/curio
(Go)
Feb 26, 2026
Apache Airflow error reporting may expose full kwargs
Moderate
CVE-2025-65995
was published
for
apache-airflow
(pip)
Feb 21, 2026
OpenClaw session tool visibility hardening and Telegram webhook secret fallback
Moderate
CVE-2026-27004
was published
for
openclaw
(npm)
Feb 18, 2026
Libredesk has a SSRF Vulnerability in Webhooks
Moderate
CVE-2026-26957
was published
for
github.com/abhinavxd/libredesk
(Go)
Feb 18, 2026
Directus Vulnerable to Information Leakage in Existing Collections
Moderate
CVE-2025-64749
was published
for
@directus/api
(npm)
Nov 13, 2025
Actual Sync-server Gocardless service is logging sensitive data including bearer tokens and account numbers
Moderate
GHSA-xvp7-8vm8-xfxx
was published
for
@actual-app/sync-server
(npm)
Oct 20, 2025
ibexa/user login enumerates user accounts
Moderate
GHSA-q3x8-6898-23g3
was published
for
ibexa/user
(Composer)
Oct 17, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Get Function
Moderate
CVE-2025-54291
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Liferay Portal and Liferay DXP vulnerable to store Cross-site Scripting
Moderate
CVE-2025-43776
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 9, 2025
TYPO3 CMS exposes sensitive information in an error message
Moderate
CVE-2025-59016
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API