GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,638
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
193 advisories
Filter by severity
MeshCentral has unsanitized data fields
High
GHSA-c7hr-448w-65px
was published
for
meshcentral
(npm)
Aug 18, 2026
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
High
GHSA-jm78-9fvv-mhgr
was published
for
GitPython
(pip)
Aug 7, 2026
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
High
CVE-2026-71320
was published
for
nuxt
(npm)
Aug 5, 2026
hashi-vault-js has a path traversal and query parameter injection
High
CVE-2026-55100
was published
for
hashi-vault-js
(npm)
Jul 31, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
High
CVE-2026-54666
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped enum string values
High
CVE-2026-54664
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
High
CVE-2026-54661
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
High
CVE-2026-54662
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
High
CVE-2026-55404
was published
for
yt-dlp
(pip)
Jul 24, 2026
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
High
GHSA-3rp5-jjmw-4wv2
was published
for
gitpython
(pip)
Jul 24, 2026
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
High
GHSA-vwjc-v7x7-cm6g
was published
for
com.arcadedb:arcadedb-engine
(Maven)
Jul 16, 2026
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services
High
GHSA-pqg7-v6wh-3pfp
was published
for
github.com/almeidapaulopt/tsdproxy
(Go)
Jul 14, 2026
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
High
CVE-2026-55427
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Langroid: handle_message() executes user-supplied tool JSON without sender verification
High
CVE-2026-54771
was published
for
langroid
(pip)
Jul 6, 2026
Flawfinder output manipulation via untrusted filenames and source text
High
CVE-2026-48813
was published
for
flawfinder
(pip)
Jun 26, 2026
Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
High
CVE-2026-54329
was published
for
snipe/snipe-it
(Composer)
Jun 23, 2026
OpenAM has LDAP Injection via `_queryId` Parameter
High
CVE-2026-41573
was published
for
org.openidentityplatform.openam:openam-core-rest
(Maven)
Jun 22, 2026
containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
High
CVE-2026-53488
was published
for
github.com/containerd/containerd
(Go)
Jun 19, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
High
CVE-2026-57209
was published
for
github.com/dadrus/heimdall
(Go)
Jun 18, 2026
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
High
CVE-2026-50574
was published
for
yt-dlp
(pip)
Jun 16, 2026
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
High
CVE-2025-27511
was published
for
org.geoserver.extension:gs-db2
(Maven)
Jun 11, 2026
Froxlor: BIND Zone File Injection via TXT Record Content
High
CVE-2026-41234
was published
for
froxlor/froxlor
(Composer)
Jun 3, 2026
Froxlor has an incomplete fix for CVE-2026-30932
High
CVE-2026-41237
was published
for
froxlor/froxlor
(Composer)
May 29, 2026
Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
High
CVE-2026-42334
was published
for
mongoose
(npm)
May 5, 2026
AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters
High
GHSA-27qh-8cxx-2cr5
was published
for
aws/aws-sdk-php
(Composer)
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API