GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,587 advisories
Filter by severity
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
Low
CVE-2026-55785
was published
for
github.com/free5gc/ausf
(Go)
Aug 28, 2026
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI
Low
CVE-2026-55891
was published
for
privatebin/privatebin
(Composer)
Aug 28, 2026
Apache Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties
Low
CVE-2026-46584
was published
for
org.apache.camel:camel-mail
(Maven)
Jul 6, 2026
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
Low
CVE-2026-55588
was published
for
oras.land/oras
(Go)
Aug 28, 2026
Snipe-IT has a path traversal vulnerability via CSV import `image` field
Low
CVE-2026-55469
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
Low
CVE-2026-42350
was published
for
github.com/akuity/kargo
(Go)
Aug 27, 2026
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions
Low
CVE-2026-54713
was published
for
cakephp/queue
(Composer)
Aug 27, 2026
OpenSTAManager has HTML Injection in modules/utenti/edit.php
Low
CVE-2026-44701
was published
for
devcode-it/openstamanager
(Composer)
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
CVE-2026-54786
was published
for
wasmtime-wasi
(Rust)
Aug 26, 2026
kas Persistently Disables SSH Host Key Checking
Low
CVE-2026-54548
was published
for
kas
(pip)
Aug 26, 2026
Duplicate Advisory: utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
Low
GHSA-vg9f-q4xh-62r4
was published
for
utcp-gql
(pip)
Jun 15, 2026
•
withdrawn
Subrion CMS vulnerable to Cross-site Scripting
Low
CVE-2026-12202
was published
for
intelliants/subrion
(Composer)
Jun 15, 2026
netfoil vulnerable to improper handling of untrusted DoH response data
Low
GHSA-4ph6-mjv7-3fq6
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Aug 24, 2026
Spring Web Services: WSS4J validation does not use configured replay cache
Low
CVE-2026-41000
was published
for
org.springframework.ws:spring-ws-security
(Maven)
Jun 11, 2026
Wagtail: Identification of documents by SHA1 hash
Low
GHSA-92hv-j533-69wc
was published
for
wagtail
(pip)
Aug 20, 2026
Winter: Stored XSS through Backend List widget image columns
Low
GHSA-7mpf-4465-7fc2
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Fleet: ORDER BY column injection on activity list endpoints
Low
GHSA-rxhg-vcww-2mpw
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 20, 2026
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
Low
GHSA-22w5-2fxg-vrwx
was published
for
github.com/opentofu/opentofu
(Go)
Aug 20, 2026
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
Low
GHSA-h58c-xccx-75m3
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Low
GHSA-8fxq-53rx-ph5f
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
BuildKit has a possible runtime DoS via unbounded group parsing
Low
CVE-2026-61712
was published
for
github.com/moby/buildkit
(Go)
Aug 19, 2026
MobSF has SSRF port restriction bypass in assetlinks_check
Low
CVE-2026-68927
was published
for
mobsf
(pip)
Aug 18, 2026
MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
Low
CVE-2026-63641
was published
for
magicmirror
(npm)
Aug 18, 2026
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
Low
CVE-2026-61634
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Low
CVE-2026-10775
was published
for
sglang
(pip)
Jun 4, 2026
ProTip!
Advisories are also available from the
GraphQL API