GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
462 advisories
Filter by severity
MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
Low
CVE-2026-63641
was published
for
magicmirror
(npm)
Aug 18, 2026
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
Low
CVE-2026-71849
was published
for
hono
(npm)
Aug 7, 2026
Mermaid configuration APIs allow prototype pollution
Low
CVE-2026-71438
was published
for
mermaid
(npm)
Aug 6, 2026
Electron: Cross-origin iframe can position native autofill popup
Low
CVE-2026-70600
was published
for
electron
(npm)
Aug 5, 2026
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
Low
CVE-2026-70598
was published
for
electron
(npm)
Aug 5, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Low
CVE-2026-53607
was published
for
apostrophe
(npm)
Jul 31, 2026
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
Low
GHSA-pc2w-4mq8-32qw
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 29, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
Low
GHSA-464c-974j-9xm6
was published
for
@aws-cdk/aws-codebuild
(Go)
Jul 24, 2026
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
Low
GHSA-c2j3-45gr-mqc4
was published
for
dompurify
(npm)
Jul 21, 2026
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
Low
CVE-2026-73425
was published
for
@astrojs/netlify
(npm)
Jul 20, 2026
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
Low
CVE-2026-12590
was published
for
body-parser
(npm)
Jul 20, 2026
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
Low
CVE-2026-59730
was published
for
@astrojs/node
(npm)
Jul 20, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Low
CVE-2026-59727
was published
for
astro
(npm)
Jul 20, 2026
Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
Low
CVE-2026-54335
was published
for
@feathersjs/commons
(npm)
Jul 14, 2026
Waku has an Open Redirect via `unstable_redirect` Helper
Low
CVE-2026-49456
was published
for
waku
(npm)
Jul 8, 2026
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Low
GHSA-2vg6-77g8-24mp
was published
for
@better-auth/scim
(npm)
Jul 7, 2026
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
Low
GHSA-3wqp-prf6-2m72
was published
for
openclaw
(npm)
Jul 2, 2026
@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
Low
GHSA-rp72-5v5q-2446
was published
for
@cardano402/mcp-server
(npm)
Jun 26, 2026
neotoma has tenant isolation gap in relationship query endpoints
Low
GHSA-wrr4-782v-jhwh
was published
for
neotoma
(npm)
Jun 25, 2026
parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change
Low
GHSA-97pr-9hgg-3p8r
was published
for
parse-server
(npm)
Jun 19, 2026
Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe
Low
GHSA-h5jc-78hr-3pc9
was published
for
@sveltia/cms
(npm)
Jun 19, 2026
parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
Low
CVE-2026-55778
was published
for
parse-server
(npm)
Jun 19, 2026
parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist
Low
CVE-2026-53724
was published
for
parse-server
(npm)
Jun 19, 2026
OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
Low
GHSA-9wxg-vf3r-56hc
was published
for
@openzeppelin/wizard
(npm)
Jun 19, 2026
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
Low
CVE-2026-11525
was published
for
undici
(npm)
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API