GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
534 advisories
Filter by severity
Mail: Email address spoofing via malformed RFC 2047 encoded-words
Moderate
CVE-2026-63435
was published
for
mail
(RubyGems)
Sep 2, 2026
Nokogiri XSLT transform has a memory leak
Moderate
CVE-2026-79771
was published
for
nokogiri
(RubyGems)
May 6, 2026
Duplicate Advisory: Nokogiri XSLT transform has a memory leak
Moderate
GHSA-rh9x-7xjc-vwx2
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
Nokogiri does not check the return value from xmlC14NExecute
Moderate
CVE-2026-79772
was published
for
nokogiri
(RubyGems)
Feb 18, 2026
Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute
Moderate
GHSA-xqqh-3w52-q8p7
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
websocket-driver: Memory exhaustion in HTTP header parser
Moderate
CVE-2026-54465
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Moderate
CVE-2026-54464
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Moderate
CVE-2026-54463
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Moderate
CVE-2026-73648
was published
for
rails-html-sanitizer
(RubyGems)
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
Moderate
CVE-2026-73490
was published
for
loofah
(RubyGems)
Jul 21, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
Moderate
CVE-2026-73428
was published
for
action_text-trix
(RubyGems)
Jul 24, 2026
Trix has a Stored XSS vulnerability through serialized attributes
Moderate
CVE-2026-73426
was published
for
action_text-trix
(RubyGems)
Mar 12, 2026
katello: missing repository authorization in content_uploads exposes cross-product content existence
Moderate
CVE-2026-12515
was published
for
katello
(RubyGems)
Jun 17, 2026
guard-livereload has a directory traversal vulnerability
Moderate
CVE-2016-1000305
was published
for
guard-livereload
(RubyGems)
Jul 31, 2026
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
Moderate
CVE-2026-67430
was published
for
mcp
(RubyGems)
Jul 30, 2026
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
Moderate
CVE-2026-63119
was published
for
mcp
(RubyGems)
Jul 30, 2026
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
Moderate
CVE-2026-63118
was published
for
mcp
(RubyGems)
Jul 30, 2026
Pagy I18n locale option is not validated before being used in a file path
Moderate
CVE-2026-54659
was published
for
pagy
(RubyGems)
Jul 28, 2026
net-imap vulnerable to command Injection via unvalidated Symbol inputs
Moderate
CVE-2026-42258
was published
for
net-imap
(RubyGems)
May 4, 2026
Excon does not redact additional sensitive/risky headers when following redirects
Moderate
CVE-2026-54171
was published
for
excon
(RubyGems)
Jul 10, 2026
decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embeds
Moderate
CVE-2024-45594
was published
for
decidim-meetings
(RubyGems)
Nov 13, 2024
ViewComponent: Reused Component Instances Retain Stale Render Context
Moderate
CVE-2026-54497
was published
for
view_component
(RubyGems)
Jul 15, 2026
Decidim: Push subscriptions can be abused for server-side requests
Moderate
CVE-2026-45573
was published
for
decidim-core
(RubyGems)
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
Moderate
CVE-2026-45572
was published
for
decidim-core
(RubyGems)
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
Moderate
CVE-2026-45415
was published
for
decidim-verifications
(RubyGems)
Jul 13, 2026
ProTip!
Advisories are also available from the
GraphQL API