GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
105 advisories
Filter by severity
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
Moderate
CVE-2026-54082
was published
for
org.verapdf:validation-model
(Maven)
Jul 29, 2026
GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
Moderate
CVE-2025-58175
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 12, 2026
Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference
Moderate
CVE-2026-40991
was published
for
org.springframework.restdocs:spring-restdocs-restassured
(Maven)
Jun 10, 2026
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
Moderate
CVE-2026-44018
was published
for
docling
(pip)
Jun 3, 2026
Apache CXF's WS-Transfer module has an insecure XML parser configuration
Moderate
CVE-2026-44618
was published
for
org.apache.cxf:cxf-rt-ws-transfer
(Maven)
May 26, 2026
TYPO3 ke_search XML External Entity Injection
Moderate
CVE-2026-46722
was published
for
tpwd/ke_search
(Composer)
May 19, 2026
Grav is Vulnerable to XXE via SVG Upload
Moderate
GHSA-3446-6mgw-f79p
was published
for
getgrav/grav
(Composer)
May 5, 2026
jOpenDocument has an improper restriction of XML external entity reference vulnerability
Moderate
CVE-2026-6501
was published
for
org.jopendocument:jOpenDocument
(Maven)
May 4, 2026
esaml XXE vulnerability allows local file disclosure and SSRF via crafted SAML messages
Moderate
CVE-2026-28809
was published
for
esaml
(Erlang)
Mar 23, 2026
Apache Syncope: Console XXE on Keymaster parameters
Moderate
CVE-2026-23795
was published
for
org.apache.syncope.client.idrepo:syncope-client-idrepo-console
(Maven)
Feb 3, 2026
Bio-Formats has an XML External Entity (XXE) vulnerability
Moderate
CVE-2026-22186
was published
for
ome:pom-bio-formats
(Maven)
Jan 7, 2026
Apache SIS has Improper Restriction of XML External Entity Reference vulnerability
Moderate
CVE-2025-68280
was published
for
org.apache.sis.core:sis-metadata
(Maven)
Jan 5, 2026
Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
Moderate
CVE-2025-68463
was published
for
biopython
(pip)
Dec 18, 2025
Peppol-py is vulnerable to XXE attacks due to Saxon configuration
Moderate
CVE-2025-66371
was published
for
peppol_py
(pip)
Nov 28, 2025
WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks
Moderate
CVE-2025-10713
was published
for
org.wso2.carbon.mediation:org.wso2.carbon.localentry
(Maven)
Nov 5, 2025
DSpace is vulnerable to XML External Entity injection during archive imports
Moderate
CVE-2025-53621
was published
for
org.dspace:dspace-api
(Maven)
Jul 15, 2025
Eclipse JGit XML External Entity (XXE) Vulnerability
Moderate
CVE-2025-4949
was published
for
org.eclipse.jgit:org.eclipse.jgit
(Maven)
May 21, 2025
Sulu vulnerable to XXE in SVG File upload Inspector
Moderate
CVE-2025-47778
was published
for
sulu/sulu
(Composer)
May 15, 2025
LocalS3 XML Parser Vulnerable to XML External Entity (XXE) Injection
Moderate
GHSA-47qw-ccjm-9c2c
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 Project Vulnerable to XML External Entity (XXE) Injection via Bucket Tagging API
Moderate
GHSA-v232-254c-m6p7
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 Project Bucket Operations Vulnerable to XML External Entity (XXE) Injection
Moderate
GHSA-2466-4485-4pxj
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 CreateBucketConfiguration Endpoint XML External Entity (XXE) Injection
Moderate
CVE-2025-27136
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
unstructured XML External Entity (XXE)
Moderate
CVE-2024-46455
was published
for
unstructured
(pip)
Dec 9, 2024
SimpleSAMLphp SAML2 has an XXE in parsing SAML messages
Moderate
CVE-2024-52806
was published
for
simplesamlphp/saml2
(Composer)
Dec 2, 2024
Apache XML Graphics FOP XML External Entity Reference ('XXE') vulnerability
Moderate
CVE-2024-28168
was published
for
org.apache.xmlgraphics:fop-core
(Maven)
Oct 9, 2024
ProTip!
Advisories are also available from the
GraphQL API