GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
172 advisories
Filter by severity
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
Moderate
CVE-2026-55087
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
Moderate
CVE-2026-62899
was published
for
Microsoft.NETCore.App.Runtime.linux-arm
(NuGet)
Aug 11, 2026
h2: Duplicate Host header could facilitate request smuggling
Moderate
CVE-2026-71554
was published
for
h2
(pip)
Aug 6, 2026
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
High
CVE-2026-71324
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
AIOHTTP: HTTP request smuggling via WebSocket upgrade
Moderate
CVE-2026-69243
was published
for
aiohttp
(pip)
Aug 3, 2026
undici vulnerable to downstream response desynchronization via retry interceptor
Moderate
CVE-2026-16728
was published
for
undici
(npm)
Aug 3, 2026
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
High
CVE-2026-73495
was published
for
org.http4s:blaze-http_2.12
(Maven)
Jul 24, 2026
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
High
CVE-2026-73494
was published
for
org.http4s:blaze-http_2.13
(Maven)
Jul 24, 2026
swift-nio-http2: Missing CR/LF/NUL validation in header values
Moderate
CVE-2026-64785
was published
for
swift-nio-http2
(Swift)
Jul 24, 2026
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
Moderate
CVE-2026-59900
was published
for
io.netty:netty-codec-http2
(Maven)
Jul 22, 2026
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
Moderate
CVE-2026-59898
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
mint: Content-Length header accepts non-RFC "+" sign prefix
Moderate
CVE-2026-49753
was published
for
mint
(Erlang)
Jul 9, 2026
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
High
CVE-2026-50197
was published
for
github.com/zalando/skipper
(Go)
Jul 8, 2026
PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling
High
CVE-2026-48979
was published
for
php-standard-library/h2
(Composer)
Jun 26, 2026
http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`
Moderate
GHSA-jrpc-7vxp-69p6
was published
for
org.http4k:http4k-core
(Maven)
Jun 19, 2026
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
High
CVE-2026-52845
was published
for
github.com/caddyserver/caddy
(Go)
Jun 16, 2026
Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
Moderate
CVE-2026-50020
was published
for
io.netty:netty-codec-http
(Maven)
Jun 15, 2026
python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
Low
CVE-2026-53538
was published
for
python-multipart
(pip)
Jun 15, 2026
SwiftNIO HTTP/2: HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec
Moderate
CVE-2026-28898
was published
for
github.com/apple/swift-nio-http2
(Swift)
Jun 12, 2026
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
Moderate
CVE-2026-41853
was published
for
org.springframework:spring-webflux
(Maven)
Jun 9, 2026
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
Moderate
CVE-2026-47676
was published
for
hono
(npm)
Jun 4, 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
Moderate
CVE-2026-48710
was published
for
starlette
(pip)
Jun 4, 2026
daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators
Low
CVE-2026-44546
was published
for
daphne
(pip)
Jun 3, 2026
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
Low
CVE-2026-46342
was published
for
@nuxt/nitro-server
(npm)
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API