GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
461 advisories
Filter by severity
pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
High
GHSA-vx52-2968-3vc6
was published
for
pnpm
(npm)
Sep 1, 2026
MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
High
GHSA-3f6p-5ww8-9rcr
was published
for
mysql2
(npm)
Sep 1, 2026
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the ...
High
Unreviewed
CVE-2026-82288
was published
Aug 28, 2026
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
High
CVE-2026-55215
was published
for
mariadb
(npm)
Aug 28, 2026
gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based...
High
Unreviewed
CVE-2026-82255
was published
Aug 28, 2026
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not...
High
Unreviewed
CVE-2026-82247
was published
Aug 28, 2026
A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter...
High
Unreviewed
CVE-2026-64632
was published
Aug 27, 2026
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected...
High
Unreviewed
CVE-2026-75960
was published
Aug 26, 2026
urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage
High
CVE-2026-55553
was published
for
urllib
(npm)
Aug 25, 2026
Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow...
High
Unreviewed
CVE-2026-76839
was published
Aug 25, 2026
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that...
High
Unreviewed
CVE-2026-76846
was published
Aug 25, 2026
Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API...
High
Unreviewed
CVE-2026-71511
was published
Aug 24, 2026
Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields,...
High
Unreviewed
CVE-2026-72857
was published
Aug 14, 2026
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped...
High
Unreviewed
CVE-2026-72801
was published
Aug 12, 2026
Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve...
High
Unreviewed
CVE-2026-12984
was published
Aug 10, 2026
SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will...
High
Unreviewed
CVE-2026-15977
was published
Jul 30, 2026
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
High
CVE-2026-67425
was published
for
flyto-core
(pip)
Jul 30, 2026
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
High
CVE-2026-67427
was published
for
flyto-core
(pip)
Jul 30, 2026
CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication...
High
Unreviewed
CVE-2026-14354
was published
Jul 29, 2026
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
High
CVE-2026-54660
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive...
High
Unreviewed
CVE-2026-46458
was published
Jul 15, 2026
CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that...
High
Unreviewed
CVE-2026-48295
was published
Jul 15, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database
High
CVE-2026-53603
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv...
High
Unreviewed
CVE-2026-59261
was published
Jul 8, 2026
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect...
High
Unreviewed
CVE-2026-7017
was published
Jul 7, 2026
ProTip!
Advisories are also available from the
GraphQL API