GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
63 advisories
Filter by severity
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
Moderate
CVE-2026-55529
was published
for
PraisonAI
(pip)
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
Moderate
CVE-2026-67448
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
Moderate
CVE-2026-70599
was published
for
electron
(npm)
Aug 5, 2026
Guzzle: Noncanonical cookie domain keeps subdomain scope
Moderate
CVE-2026-69245
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
Moderate
CVE-2026-63118
was published
for
mcp
(RubyGems)
Jul 30, 2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Moderate
CVE-2026-73419
was published
for
@auth/core
(npm)
Jul 23, 2026
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
Moderate
CVE-2026-59883
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data
Moderate
CVE-2026-53656
was published
for
fiftyone
(pip)
Jul 15, 2026
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
Moderate
CVE-2026-55438
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
Moderate
CVE-2026-46611
was published
for
glances
(pip)
Jun 22, 2026
dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
Moderate
CVE-2026-55837
was published
for
dbt-mcp
(pip)
Jun 19, 2026
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
Moderate
CVE-2026-55767
was published
for
guzzlehttp/guzzle
(Composer)
Jun 19, 2026
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
Moderate
CVE-2026-55669
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
Moderate
CVE-2026-9595
was published
for
webpack-dev-server
(npm)
Jun 17, 2026
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
Moderate
CVE-2026-48022
was published
for
@hapi/wreck
(npm)
Jun 11, 2026
gun_http2 has an Origin Validation Error vulnerability
Moderate
CVE-2026-43972
was published
for
gun
(Erlang)
Jun 8, 2026
sanic-cors contains an improper regular expression in the try_match() function
Moderate
CVE-2026-37737
was published
for
sanic-cors
(pip)
Jun 5, 2026
AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
Moderate
CVE-2026-47265
was published
for
aiohttp
(pip)
Jun 3, 2026
Duplicate Advisory: jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used
Moderate
CVE-2026-6657
was published
for
jupyter-server
(pip)
Jun 3, 2026
•
withdrawn
Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint
Moderate
CVE-2026-6339
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
Moderate
CVE-2026-45021
was published
for
github.com/kumahq/kuma
(Go)
May 14, 2026
@cyclonedx/cdxgen: Docker registry auth substring match forwards credentials to a different registry
Moderate
GHSA-qhh4-458h-xwh2
was published
for
@cyclonedx/cdxgen
(npm)
May 8, 2026
pyLoad has a Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global State Race Condition)
Moderate
CVE-2026-40594
was published
for
pyload-ng
(pip)
Apr 16, 2026
Signal K Server: OAuth Authorization Code Theft via Unvalidated Host Header in OIDC Flow
Moderate
CVE-2026-34083
was published
for
signalk-server
(npm)
Apr 3, 2026
Electron: Incorrect origin passed to permission request handler for iframe requests
Moderate
CVE-2026-34777
was published
for
electron
(npm)
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API