GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
3,368 advisories
Filter by severity
axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-248h-974q-xrc2
was published
for
com.getaxonflow:axonflow-sdk
(Maven)
May 6, 2026
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
Moderate
CVE-2026-18401
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Feb 28, 2026
Duplicate Advisory: jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
Moderate
GHSA-6qm2-mcq7-53qp
was published
for
tools.jackson.core:jackson-core
(Maven)
Aug 4, 2026
•
withdrawn
Apache Tomcat - Client certificate verification bypass
Moderate
CVE-2025-66614
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Feb 17, 2026
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
Moderate
CVE-2026-55860
was published
for
org.mariadb:r2dbc-mariadb
(Maven)
Aug 28, 2026
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
Moderate
CVE-2026-55859
was published
for
org.mariadb:r2dbc-mariadb
(Maven)
Aug 28, 2026
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context
Moderate
CVE-2026-55858
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Aug 28, 2026
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
Moderate
CVE-2026-55857
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Aug 28, 2026
MariaDB has cleartext password disclosure to a MITM on the initial-handshake
Moderate
CVE-2026-55856
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Aug 28, 2026
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
Moderate
CVE-2026-55867
was published
for
org.graylog2:graylog2-server
(Maven)
Aug 28, 2026
Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
Moderate
CVE-2026-63621
was published
for
org.apache.camel:camel-knative
(Maven)
Aug 24, 2026
Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
Moderate
CVE-2026-60093
was published
for
org.apache.camel:camel-azure-storage-datalake
(Maven)
Aug 24, 2026
Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
Moderate
CVE-2026-59230
was published
for
org.apache.camel:camel-mail
(Maven)
Aug 24, 2026
Apache Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers
Moderate
CVE-2026-49086
was published
for
org.apache.camel:camel-dapr
(Maven)
Jul 6, 2026
Apache Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter
Moderate
CVE-2026-49098
was published
for
org.apache.camel:camel-kafka
(Maven)
Jul 6, 2026
Apache Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter
Moderate
CVE-2026-49097
was published
for
org.apache.camel:camel-irc
(Maven)
Jul 6, 2026
Apache Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body
Moderate
CVE-2026-49365
was published
for
org.apache.camel:camel-netty-http
(Maven)
Jul 6, 2026
Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter
Moderate
CVE-2026-49099
was published
for
org.apache.camel:camel-salesforce
(Maven)
Jul 6, 2026
Apache Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body
Moderate
CVE-2026-56139
was published
for
org.apache.camel:camel-undertow
(Maven)
Jul 6, 2026
Apache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter
Moderate
CVE-2026-48206
was published
for
org.apache.camel:camel-jira
(Maven)
Jul 6, 2026
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
Moderate
CVE-2026-55425
was published
for
org.graylog2:graylog2-server
(Maven)
Aug 28, 2026
Yamcs has DOM XSS in Extension Routing
Moderate
CVE-2026-55566
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs has Reflected XSS in the URL of the Authorize Endpoint
Moderate
CVE-2026-55549
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
Moderate
CVE-2026-55548
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
Moderate
CVE-2026-55547
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API