GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
12,566 advisories
Filter by severity
libp2p nodes vulnerable to attack using large RSA keys
High
CVE-2023-39533
was published
for
github.com/libp2p/go-libp2p
(Go)
Aug 9, 2023
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
High
CVE-2026-84304
was published
for
google.golang.org/grpc
(Go)
Sep 1, 2026
TYPO3 CMS - Broken Access Control in Backend and Install Tool
High
CVE-2026-19418
was published
for
typo3/cms-backend
(Composer)
Sep 1, 2026
Duplicate Advisory: TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool
High
GHSA-4f2f-jr2m-j7p4
was published
for
typo3/cms-core
(Composer)
Aug 11, 2026
•
withdrawn
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
High
CVE-2026-77567
was published
for
filament/filament
(Composer)
Sep 1, 2026
SAP Approuter has an Information Disclosure vulnerability
High
CVE-2026-58230
was published
for
@sap/approuter
(npm)
Aug 11, 2026
SAP Approuter has an Open Redirect vulnerability
High
CVE-2026-44745
was published
for
@sap/approuter
(npm)
Jul 14, 2026
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
High
CVE-2026-72778
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Duplicate Advisory: Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
High
GHSA-w36c-qxrq-v7fw
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
Duplicate Advisory: Craft CMS: Authenticated leak of secret environment variables
High
GHSA-cc2g-26rw-g997
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
Apache Airflow Vulnerable to Deserialization of Untrusted Data
High
CVE-2026-45360
was published
for
apache-airflow
(pip)
Jun 1, 2026
Craft CMS: Authenticated RCE through Twig sandbox escape
High
CVE-2026-72781
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Duplicate Advisory: Craft CMS: Authenticated RCE through Twig sandbox escape
High
GHSA-h784-hpjp-2rrm
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
Duplicate Advisory: Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
High
GHSA-2p2v-3mjg-gfpf
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
High
CVE-2026-56740
was published
for
org.jline:jline-remote-telnet
(Maven)
Jun 18, 2026
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
High
CVE-2026-56741
was published
for
org.jline:jline-remote-telnet
(Maven)
Jun 18, 2026
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
High
GHSA-8rr7-cvq3-gmfh
was published
for
league/commonmark
(Composer)
Sep 1, 2026
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
High
CVE-2026-78680
was published
for
nltk
(pip)
Sep 1, 2026
Duplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427)
High
GHSA-54xp-3ww7-6wjg
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
league/commonmark: Denial of service in the SmartPunct and Attributes extensions
High
GHSA-jjv6-8j6v-6j52
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
High
GHSA-j8pm-gj4c-rq4x
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
High
GHSA-f8fg-pg57-v4j8
was published
for
league/commonmark
(Composer)
Sep 1, 2026
nanoid: Integer Overflow or Wraparound
High
CVE-2026-73086
was published
for
nanoid
(npm)
Sep 1, 2026
pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
High
GHSA-vx52-2968-3vc6
was published
for
pnpm
(npm)
Sep 1, 2026
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
High
GHSA-2rx9-3g3h-c2jv
was published
for
pnpm
(npm)
Sep 1, 2026
ProTip!
Advisories are also available from the
GraphQL API