GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
7,203 advisories
Filter by severity
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77415
was published
for
jsonata
(npm)
Aug 21, 2026
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77414
was published
for
jsonata
(npm)
Aug 21, 2026
JSONata: Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77413
was published
for
jsonata
(npm)
Aug 21, 2026
Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
High
CVE-2026-63421
was published
for
@keystone-6/core
(npm)
Aug 21, 2026
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
High
CVE-2026-61824
was published
for
defuddle
(npm)
Aug 21, 2026
Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
Moderate
CVE-2026-63466
was published
for
unleash-server
(npm)
Aug 21, 2026
Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
Moderate
CVE-2026-63004
was published
for
unleash-server
(npm)
Aug 21, 2026
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
High
CVE-2026-63462
was published
for
unleash-server
(npm)
Aug 21, 2026
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
Moderate
CVE-2026-55451
was published
for
gettext-converter
(npm)
Aug 20, 2026
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
High
GHSA-ghvf-qf6h-g8x5
was published
for
@nocobase/server
(npm)
Aug 20, 2026
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication
Critical
CVE-2026-55445
was published
for
@whyour/qinglong
(npm)
Aug 20, 2026
node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS
High
CVE-2026-54156
was published
for
node-opcua
(npm)
Aug 20, 2026
node-opcua missing nonce verification in UserNameIdentityToken authentication
High
CVE-2026-54155
was published
for
node-opcua
(npm)
Aug 20, 2026
next-video: Unauthenticated arbitrary file read via /api/video request handler
Moderate
CVE-2026-54150
was published
for
next-video
(npm)
Aug 20, 2026
NocoBase backup restore schema name allows command injection
Moderate
CVE-2026-55410
was published
for
@nocobase/plugin-backups
(npm)
Aug 20, 2026
Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root
Moderate
CVE-2026-63123
was published
for
@tinacms/cli
(npm)
Aug 19, 2026
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
Moderate
CVE-2026-59992
was published
for
next-tinacms-azure
(npm)
Aug 19, 2026
logto-tunnel serves files outside --experience-path via path traversal
High
CVE-2026-63188
was published
for
@logto/tunnel
(npm)
Aug 19, 2026
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
Moderate
GHSA-hjwh-xvfw-qrwj
was published
for
mcp-searxng
(npm)
Aug 19, 2026
SearXNG MCP Server: Additional hardened-mode SSRF bypasses
Moderate
CVE-2026-54689
was published
for
mcp-searxng
(npm)
Aug 19, 2026
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Moderate
CVE-2026-54688
was published
for
mcp-searxng
(npm)
Aug 19, 2026
Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
High
CVE-2026-53957
was published
for
@contentful/mcp-server
(npm)
Aug 19, 2026
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-rr55-jp92-8wp2
was published
for
claude-faf-mcp
(npm)
Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-j4r7-8ph4-43g3
was published
for
faf-mcp
(npm)
Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
High
GHSA-cc2g-gq8c-r332
was published
for
grok-faf-mcp
(npm)
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API