GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,339 advisories
Filter by severity
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
High
CVE-2026-56740
was published
for
org.jline:jline-remote-telnet
(Maven)
Jun 18, 2026
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
High
CVE-2026-56741
was published
for
org.jline:jline-remote-telnet
(Maven)
Jun 18, 2026
OpenMetadata's Server-Side Template Injection (SSTI) in FreeMarker email templates leads to RCE
High
CVE-2026-22244
was published
for
org.open-metadata:platform
(Maven)
Jan 7, 2026
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types
High
CVE-2026-44795
was published
for
io.spinnaker.orca:orca-core
(Maven)
Jun 22, 2026
MapFish Print has XXE that allows reading arbitrary files of certain types
High
CVE-2026-55848
was published
for
org.mapfish.print:print-lib
(Maven)
Aug 28, 2026
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
High
CVE-2026-55841
was published
for
org.graylog2:graylog2-server
(Maven)
Aug 28, 2026
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
High
CVE-2026-66908
was published
for
org.apache.camel:camel-platform-http-main
(Maven)
Aug 24, 2026
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
High
CVE-2026-66907
was published
for
org.apache.camel:camel-google-storage
(Maven)
Aug 24, 2026
Apache Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy
High
CVE-2026-46726
was published
for
org.apache.camel:camel-vertx-websocket
(Maven)
Jul 6, 2026
Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters
High
CVE-2026-49042
was published
for
org.apache.camel:camel-langchain4j-agent
(Maven)
Jul 6, 2026
Apache Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy
High
CVE-2026-55993
was published
for
org.apache.camel:camel-atmosphere-websocket
(Maven)
Jul 6, 2026
Apache Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy
High
CVE-2026-55994
was published
for
org.apache.camel:camel-iggy
(Maven)
Jul 6, 2026
Apache Camel-CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
High
CVE-2026-46588
was published
for
org.apache.camel:camel-couchdb
(Maven)
Jul 6, 2026
Apache Camel-Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
High
CVE-2026-46587
was published
for
org.apache.camel:camel-couchbase
(Maven)
Jul 6, 2026
Apache Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
High
CVE-2026-46592
was published
for
org.apache.camel:camel-cxf-rest
(Maven)
Jul 6, 2026
Apache Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)
High
CVE-2026-46591
was published
for
org.apache.camel:camel-neo4j
(Maven)
Jul 6, 2026
Apache Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)
High
CVE-2026-46590
was published
for
org.apache.camel:camel-pqc
(Maven)
Jul 6, 2026
Apache Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
High
CVE-2026-46585
was published
for
org.apache.camel:camel-lucene
(Maven)
Jul 6, 2026
Apache Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
High
CVE-2026-46457
was published
for
org.apache.camel:camel-nats
(Maven)
Jul 6, 2026
PowSyBl Core has Command Injection in LocalCommandExecutor-s
High
CVE-2026-55673
was published
for
com.powsybl:powsybl-computation-local
(Maven)
Aug 28, 2026
Spinnaker: Improper yaml processing on kustomize bake operations
High
CVE-2026-55175
was published
for
io.spinnaker.rosco:rosco-manifests
(Maven)
Aug 28, 2026
Yamcs has Unauthenticated Directory Traversal
High
CVE-2026-55552
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities
High
CVE-2026-55521
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation
High
CVE-2026-53435
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Apache Camel JMS deserialization filter bypass
High
CVE-2026-43866
was published
for
org.apache.camel:camel-activemq
(Maven)
Jul 6, 2026
ProTip!
Advisories are also available from the
GraphQL API