GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
34,951 advisories
Filter by severity
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
Moderate
CVE-2026-55678
was published
for
github.com/basekick-labs/arc
(Go)
Aug 28, 2026
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
High
CVE-2026-55761
was published
for
github.com/portainer/portainer
(Go)
Aug 28, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
High
CVE-2026-55763
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI
Low
CVE-2026-55891
was published
for
privatebin/privatebin
(Composer)
Aug 28, 2026
PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
Moderate
CVE-2026-55696
was published
for
privatebin/privatebin
(Composer)
Aug 28, 2026
AIIR verification and policy gates could report success without enforcing the control (fail-open)
Moderate
GHSA-73p9-6hrp-8qhr
was published
for
aiir
(pip)
Aug 28, 2026
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
High
CVE-2026-55484
was published
for
github.com/guno1928/alos-http
(Go)
Aug 28, 2026
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
Critical
CVE-2026-55634
was published
for
pimcore/pimcore
(Composer)
Aug 28, 2026
Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)
Critical
CVE-2026-55220
was published
for
pimcore/pimcore
(Composer)
Aug 28, 2026
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
High
CVE-2026-55212
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
High
CVE-2026-55208
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
High
CVE-2026-55207
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
High
CVE-2026-55215
was published
for
mariadb
(npm)
Aug 28, 2026
plone.app.event vulnerable to denial of service via iCalendar import
Critical
CVE-2026-55247
was published
for
plone.app.event
(pip)
Aug 28, 2026
Incus has a project restriction bypass in instance copy across projects
High
CVE-2026-55622
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Aug 28, 2026
Incus has a project restriction bypass for custom volume copy across projects
High
CVE-2026-55621
was published
for
github.com/lxc/incus
(Go)
Aug 28, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
High
CVE-2026-55228
was published
for
Weblate
(pip)
Aug 28, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
Moderate
CVE-2026-55227
was published
for
weblate
(pip)
Aug 28, 2026
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
High
CVE-2026-55520
was published
for
Protego
(pip)
Aug 28, 2026
plone.app.portlets vulnerable to denial of service via RSS feed portlet
Critical
CVE-2026-55248
was published
for
plone.app.portlets
(pip)
Aug 28, 2026
PowSyBl Core has Command Injection in LocalCommandExecutor-s
High
CVE-2026-55673
was published
for
com.powsybl:powsybl-computation-local
(Maven)
Aug 28, 2026
Spinnaker: Improper yaml processing on kustomize bake operations
High
CVE-2026-55175
was published
for
io.spinnaker.rosco:rosco-manifests
(Maven)
Aug 28, 2026
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
Moderate
CVE-2026-55407
was published
for
buffa
(Rust)
Aug 28, 2026
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
Moderate
CVE-2026-55406
was published
for
buffa
(Rust)
Aug 28, 2026
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
High
CVE-2026-55641
was published
for
9router
(npm)
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API