GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,535
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,515
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
45 advisories
Filter by severity
MagicMirror: ssrf calendar .js
Moderate
CVE-2026-63643
was published
for
magicmirror
(npm)
Aug 18, 2026
The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an...
Moderate
Unreviewed
CVE-2026-72640
was published
Aug 13, 2026
A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create...
Moderate
Unreviewed
CVE-2026-16456
was published
Aug 10, 2026
The OnCallNotificationActivity in the Datadog Android application is declared android:exported=...
Moderate
Unreviewed
CVE-2026-44964
was published
Aug 7, 2026
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
Moderate
CVE-2026-54663
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
Astro: Unauthenticated path override in the @astrojs/vercel ISR function
Moderate
CVE-2026-73424
was published
for
@astrojs/vercel
(npm)
Jul 20, 2026
An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior...
Moderate
Unreviewed
CVE-2026-12879
was published
Jul 9, 2026
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
Moderate
CVE-2026-55430
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
Moderate
CVE-2026-9595
was published
for
webpack-dev-server
(npm)
Jun 17, 2026
NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
Moderate
CVE-2026-53931
was published
for
nocodb
(npm)
Jun 17, 2026
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
Moderate
CVE-2026-48522
was published
for
PyJWT
(pip)
Jun 15, 2026
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
Moderate
CVE-2026-50169
was published
for
@angular/service-worker
(npm)
Jun 15, 2026
Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection
Moderate
CVE-2026-47122
was published
for
github.com/sparkle-project/Sparkle
(Swift)
May 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18...
Moderate
Unreviewed
CVE-2026-3160
was published
May 14, 2026
Duplicate Advisory: OpenClaw: Workspace dotenv files cannot override connector endpoint hosts
Moderate
GHSA-5jgm-f9wr-9qm7
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
Moderate
GHSA-4mhr-cxr4-2prm
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API
Moderate
GHSA-8pf2-vj79-4wxg
was published
for
openclaw
(npm)
Apr 28, 2026
•
withdrawn
Kratos has a Confused Deputy issue
Moderate
CVE-2026-6993
was published
for
github.com/go-kratos/kratos/v2
(Go)
Apr 25, 2026
Aiven Operator has cross-namespace secret exfiltration via ClickhouseUser connInfoSecretSource
Moderate
CVE-2026-39961
was published
for
github.com/aiven/aiven-operator
(Go)
Apr 10, 2026
Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
Moderate
CVE-2025-62718
was published
for
axios
(npm)
Apr 9, 2026
Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`
Moderate
CVE-2026-33768
was published
for
@astrojs/vercel
(npm)
Mar 26, 2026
OliveTin's RestartAction always runs actions as guest
Moderate
CVE-2026-30225
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries
Moderate
CVE-2025-68944
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
In onCreateTasks of CameraActivity.java, there is a possible permission bypass due to a confused...
Moderate
Unreviewed
CVE-2025-36889
was published
Dec 11, 2025
In multiple locations, there is a possible way to alter the primary user's face unlock settings...
Moderate
Unreviewed
CVE-2025-48598
was published
Dec 8, 2025
ProTip!
Advisories are also available from the
GraphQL API