GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
15,029 advisories
Filter by severity
s2n-quic has excessive memory allocation
Moderate
CVE-2026-10740
was published
for
s2n-quic
(Rust)
Aug 14, 2026
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
Moderate
CVE-2026-55156
was published
for
@ooples/token-optimizer-mcp
(npm)
Aug 14, 2026
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Moderate
CVE-2026-53708
was published
for
mcp-contextforge-gateway
(pip)
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
Moderate
GHSA-8rw6-p7m8-63jp
was published
for
surrealdb
(Rust)
Aug 14, 2026
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Moderate
CVE-2026-53658
was published
for
github.com/hyperledger/fabric-ca
(Go)
Aug 14, 2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Moderate
CVE-2026-73559
was published
for
vllm
(pip)
Aug 13, 2026
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Moderate
CVE-2026-54249
was published
for
pydantic-ai
(pip)
Aug 13, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors
Moderate
CVE-2026-55102
was published
for
hashi-vault-js
(npm)
Aug 13, 2026
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
Moderate
CVE-2026-55088
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
Moderate
CVE-2026-55086
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
Moderate
CVE-2026-55087
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
Moderate
CVE-2026-48786
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 12, 2026
phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration
Moderate
CVE-2026-47132
was published
for
thorsten/phpmyfaq
(Composer)
Aug 12, 2026
LibreNMS: Reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignment
Moderate
CVE-2026-45694
was published
for
librenms/librenms
(Composer)
Aug 12, 2026
Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
Moderate
CVE-2026-32639
was published
for
winter/wn-cms-module
(Composer)
Aug 12, 2026
Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax
Moderate
CVE-2026-32593
was published
for
winter/wn-backend-module
(Composer)
Aug 12, 2026
tablib: Stored XSS in the HTML export via unescaped dataset title
Moderate
CVE-2026-9318
was published
for
tablib
(pip)
Aug 12, 2026
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Moderate
CVE-2026-62902
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Aug 11, 2026
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
Moderate
CVE-2026-62909
was published
for
Microsoft.NETCore.App.Runtime.linux-arm
(NuGet)
Aug 11, 2026
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
Moderate
CVE-2026-62899
was published
for
Microsoft.NETCore.App.Runtime.linux-arm
(NuGet)
Aug 11, 2026
Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
Moderate
GHSA-4jjw-pwvw-q6w3
was published
for
nuxt
(npm)
Aug 11, 2026
•
withdrawn
pypdf: Possible large memory usage for large /ToUnicode streams
Moderate
CVE-2026-71870
was published
for
pypdf
(pip)
Aug 7, 2026
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
Moderate
CVE-2026-71852
was published
for
pypdf
(pip)
Aug 7, 2026
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
Moderate
CVE-2026-71850
was published
for
hono
(npm)
Aug 7, 2026
Hono: Algorithmic Complexity DoS in Language Middleware
Moderate
CVE-2026-71848
was published
for
hono
(npm)
Aug 7, 2026
ProTip!
Advisories are also available from the
GraphQL API