GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,339 advisories
Filter by severity
MapFish Print has XXE that allows reading arbitrary files of certain types
High
CVE-2026-55848
was published
for
org.mapfish.print:print-lib
(Maven)
Aug 28, 2026
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
High
CVE-2026-55841
was published
for
org.graylog2:graylog2-server
(Maven)
Aug 28, 2026
PowSyBl Core has Command Injection in LocalCommandExecutor-s
High
CVE-2026-55673
was published
for
com.powsybl:powsybl-computation-local
(Maven)
Aug 28, 2026
Spinnaker: Improper yaml processing on kustomize bake operations
High
CVE-2026-55175
was published
for
io.spinnaker.rosco:rosco-manifests
(Maven)
Aug 28, 2026
Yamcs has Unauthenticated Directory Traversal
High
CVE-2026-55552
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities
High
CVE-2026-55521
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
High
CVE-2026-54550
was published
for
org.codehaus.izpack:izpack-installer
(Maven)
Aug 26, 2026
http4s has HTTP/2 Denial of Service with Ember Backend
High
CVE-2026-54556
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Aug 26, 2026
Sakai Conversations has a Stored XSS Issue
High
CVE-2026-54049
was published
for
org.sakaiproject.conversations:sakai-conversations-impl
(Maven)
Aug 24, 2026
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
High
CVE-2026-66908
was published
for
org.apache.camel:camel-platform-http-main
(Maven)
Aug 24, 2026
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
High
CVE-2026-66907
was published
for
org.apache.camel:camel-google-storage
(Maven)
Aug 24, 2026
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
High
CVE-2026-63202
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
High
CVE-2026-61827
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
High
CVE-2026-63124
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
High
CVE-2026-61798
was published
for
io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl
(Maven)
Aug 20, 2026
netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service
High
CVE-2026-54251
was published
for
io.netty.incubator:netty-incubator-codec-ohttp
(Maven)
Aug 20, 2026
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
High
CVE-2024-45747
was published
for
org.geoserver.web:gs-web-app
(Maven)
Aug 19, 2026
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing
High
CVE-2026-53966
was published
for
org.xwiki.platform:xwiki-platform-livedata-livetable
(Maven)
Aug 19, 2026
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
High
CVE-2026-63337
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation
High
CVE-2026-69219
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
High
CVE-2026-69220
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
High
CVE-2026-55839
was published
for
io.kestra:kestra
(Maven)
Aug 18, 2026
http4k: `DigestAuthProvider.verify` did not bind to request URI
High
CVE-2026-54148
was published
for
org.http4k:http4k-security-digest
(Maven)
Aug 17, 2026
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
High
CVE-2026-53752
was published
for
org.docx4j:docx4j-core
(Maven)
Aug 17, 2026
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
High
CVE-2026-53659
was published
for
org.http4k:http4k-core
(Maven)
Aug 17, 2026
ProTip!
Advisories are also available from the
GraphQL API