GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
409 advisories
Filter by severity
Apache Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties
Low
CVE-2026-46584
was published
for
org.apache.camel:camel-mail
(Maven)
Jul 6, 2026
Spring Web Services: WSS4J validation does not use configured replay cache
Low
CVE-2026-41000
was published
for
org.springframework.ws:spring-ws-security
(Maven)
Jun 11, 2026
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
Low
CVE-2026-61634
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads
Low
CVE-2026-41694
was published
for
org.springframework.security:spring-security-saml2-service-provider
(Maven)
Jun 10, 2026
Spring Framework Denial of Service via AntPathMatcher
Low
CVE-2026-41848
was published
for
org.springframework:spring-core
(Maven)
Jun 9, 2026
Spring Framework Arbitrary Method Invocation in SpEL Expressions
Low
CVE-2026-41852
was published
for
org.springframework:spring-expression
(Maven)
Jun 9, 2026
hsweb-framework has a Path Traversal issue
Low
CVE-2026-11470
was published
for
org.hswebframework.web:hsweb-system-file
(Maven)
Jun 8, 2026
hsweb-framework has an open redirect issue
Low
CVE-2026-11477
was published
for
org.hswebframework.web:hsweb-authorization-oauth2
(Maven)
Jun 8, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
Low
GHSA-464c-974j-9xm6
was published
for
@aws-cdk/aws-codebuild
(Go)
Jul 24, 2026
Keycloak: Information disclosure due to user profile permission bypass
Low
CVE-2026-9088
was published
for
org.keycloak:keycloak-services
(Maven)
Jun 5, 2026
Logback vulnerable to Object Injection through HardenedObjectInputStream modules
Low
CVE-2026-10532
was published
for
ch.qos.logback:logback-core
(Maven)
Jun 1, 2026
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
Low
CVE-2026-4874
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 26, 2026
Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim
Low
CVE-2026-37977
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 6, 2026
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login
Low
CVE-2026-48589
was published
for
org.apache.shiro:shiro-jakarta-ee
(Maven)
May 26, 2026
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
Low
CVE-2026-22741
was published
for
org.springframework:spring-webflux
(Maven)
Apr 29, 2026
QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerability
Low
CVE-2026-9828
was published
for
ch.qos.logback:logback-core
(Maven)
May 28, 2026
land.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory
Low
GHSA-j6hm-v3x2-qv6j
was published
for
land.oras:oras-java-sdk
(Maven)
Jul 1, 2026
CrateDB's Blob HTTP handler bypasses authorization
Low
CVE-2026-49989
was published
for
io.crate:crate
(Maven)
Jul 1, 2026
Micronaut has Unbounded `bundleCache` in `ResourceBundleMessageSource` that Allows Memory Exhaustion via `Accept-Language` Header
Low
CVE-2026-44242
was published
for
io.micronaut:micronaut-inject
(Maven)
May 6, 2026
Sigstore Java has a vulnerability with bundle verification of integratedTime
Low
CVE-2026-48791
was published
for
dev.sigstore:sigstore-java
(Maven)
Jun 30, 2026
TCC-TRANSACTION has an Improper Input Validation vulnerability
Low
CVE-2026-9497
was published
for
org.mengyun:tcc-transaction
(Maven)
May 26, 2026
jasypt-spring-boot Uses a One-Way Hash without a Salt
Low
CVE-2026-9370
was published
for
com.github.ulisesbocchio:jasypt-spring-boot
(Maven)
May 26, 2026
Apache Tomcat - Security constraint bypass with HTTP/0.9
Low
CVE-2026-24733
was published
for
org.apache.tomcat:tomcat-coyote
(Maven)
Feb 17, 2026
OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget`
Low
CVE-2026-44793
was published
for
org.openidentityplatform.openam:openam-federation-library
(Maven)
Jun 22, 2026
Keycloak's identity-first login flow exposes user information
Low
CVE-2026-4633
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 23, 2026
ProTip!
Advisories are also available from the
GraphQL API