GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
7,054 advisories
Filter by severity
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
High
CVE-2026-56740
was published
for
org.jline:jline-remote-telnet
(Maven)
Jun 18, 2026
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
High
CVE-2026-56741
was published
for
org.jline:jline-remote-telnet
(Maven)
Jun 18, 2026
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
Moderate
CVE-2026-18401
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Feb 28, 2026
Duplicate Advisory: jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
Moderate
GHSA-6qm2-mcq7-53qp
was published
for
tools.jackson.core:jackson-core
(Maven)
Aug 4, 2026
•
withdrawn
Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames
Critical
CVE-2026-25534
was published
for
io.spinnaker.clouddriver:clouddriver-artifacts
(Maven)
Mar 16, 2026
OpenMetadata's Server-Side Template Injection (SSTI) in FreeMarker email templates leads to RCE
High
CVE-2026-22244
was published
for
org.open-metadata:platform
(Maven)
Jan 7, 2026
hermes-management is vulnerable to RCE due to Apache commons-jxpath
Critical
GHSA-2gh6-wc3m-g37f
was published
for
pl.allegro.tech.hermes:hermes-management
(Maven)
Sep 17, 2024
Apache Tomcat - Client certificate verification bypass
Moderate
CVE-2025-66614
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Feb 17, 2026
Apache Pinot Vulnerable to Authentication Bypass
Critical
CVE-2024-56325
was published
for
org.apache.pinot:pinot-broker
(Maven)
Apr 1, 2025
Apache Dolphinscheduler Code Injection vulnerability
Critical
CVE-2024-43202
was published
for
org.apache.dolphinscheduler:dolphinscheduler-task-api
(Maven)
Aug 20, 2024
Apache Polaris has an Improper Input Validation issue
Critical
CVE-2026-42812
was published
for
org.apache.polaris:polaris-runtime-service
(Maven)
May 4, 2026
Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
Critical
CVE-2024-38821
was published
for
org.springframework.security:spring-security-web
(Maven)
Oct 28, 2024
Apache Ranger UI vulnerable to Server Side Request Forgery
Critical
CVE-2024-45479
was published
for
org.apache.ranger:ranger
(Maven)
Jan 22, 2025
Apache Tomcat - HTTP/2 request headers not validated
Critical
CVE-2026-41293
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 12, 2026
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types
High
CVE-2026-44795
was published
for
io.spinnaker.orca:orca-core
(Maven)
Jun 22, 2026
Keycloak: Unauthenticated account takeover via reset-credentials flow bypass
Critical
CVE-2026-18963
was published
for
org.keycloak:keycloak-services
(Maven)
Aug 18, 2026
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
Moderate
CVE-2026-55860
was published
for
org.mariadb:r2dbc-mariadb
(Maven)
Aug 28, 2026
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
Moderate
CVE-2026-55859
was published
for
org.mariadb:r2dbc-mariadb
(Maven)
Aug 28, 2026
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context
Moderate
CVE-2026-55858
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Aug 28, 2026
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
Moderate
CVE-2026-55857
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Aug 28, 2026
MariaDB has cleartext password disclosure to a MITM on the initial-handshake
Moderate
CVE-2026-55856
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Aug 28, 2026
MapFish Print has XXE that allows reading arbitrary files of certain types
High
CVE-2026-55848
was published
for
org.mapfish.print:print-lib
(Maven)
Aug 28, 2026
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
Moderate
CVE-2026-55867
was published
for
org.graylog2:graylog2-server
(Maven)
Aug 28, 2026
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
High
CVE-2026-55841
was published
for
org.graylog2:graylog2-server
(Maven)
Aug 28, 2026
Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
Critical
CVE-2026-78329
was published
for
org.apache.camel:camel-undertow
(Maven)
Aug 24, 2026
ProTip!
Advisories are also available from the
GraphQL API