GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,538
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
26 advisories
Filter by severity
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Low
GHSA-2vg6-77g8-24mp
was published
for
@better-auth/scim
(npm)
Jul 7, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
Low
CVE-2026-35361
was published
for
uu_mknod
(Rust)
Jul 6, 2026
zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip
Moderate
CVE-2026-52733
was published
for
zebra-state
(Rust)
Jul 2, 2026
Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache
High
CVE-2026-52736
was published
for
zebra-state
(Rust)
Jul 2, 2026
Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
Moderate
CVE-2026-5038
was published
for
multer
(npm)
Jun 17, 2026
Multer vulnerable to Denial of Service via incomplete cleanup
High
CVE-2026-3304
was published
for
multer
(npm)
Mar 1, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse
Critical
CVE-2026-28268
was published
for
code.vikunja.io/api
(Go)
Feb 28, 2026
webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map
Moderate
CVE-2026-21438
was published
for
github.com/quic-go/webtransport-go
(Go)
Feb 12, 2026
Apache Struts has a Denial of Service vulnerability
High
CVE-2025-66675
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 10, 2025
Babylon Incorrect FP inactive accounting in costaking creates “phantom stake” that earns rewards after BTC unbond
Moderate
GHSA-4rmq-mc2c-r495
was published
for
github.com/babylonlabs-io/babylon
(Go)
Dec 9, 2025
Apache Struts is Vulnerable to DoS via File Leak
High
CVE-2025-64775
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 1, 2025
Apache Tomcat Denial of Service via invalid HTTP priority header
Moderate
CVE-2025-31650
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 28, 2025
SiYuan has an arbitrary file deletion vulnerability
High
CVE-2025-21609
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jan 3, 2025
Moodle HTTP authorization header is preserved between "emulated redirects"
Moderate
CVE-2024-38275
was published
for
moodle/moodle
(Composer)
Jun 18, 2024
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
Moderate
CVE-2024-23672
was published
for
org.apache.tomcat.embed:tomcat-embed-websocket
(Maven)
Mar 13, 2024
Apache Struts Improper Control of Dynamically-Managed Code Resources vulnerability
High
CVE-2023-41835
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 5, 2023
Apache Tomcat Incomplete Cleanup vulnerability
Moderate
CVE-2023-42794
was published
for
org.apache.tomcat:tomcat-coyote
(Maven)
Oct 10, 2023
Apache Tomcat Incomplete Cleanup vulnerability
Moderate
CVE-2023-42795
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 10, 2023
Upgrading doesn't prevent exploiting vulnerable XWiki documents
Critical
CVE-2023-36468
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 30, 2023
Spring Security logout not clearing security context
Moderate
CVE-2023-20862
was published
for
org.springframework.security:spring-security-core
(Maven)
Apr 19, 2023
redis-py Race Condition due to incomplete fix
High
CVE-2023-28859
was published
for
redis
(pip)
Mar 26, 2023
Apache ShardingSphere-Proxy Incomplete Cleanup vulnerability
Critical
CVE-2022-45347
was published
for
org.apache.shardingsphere:shardingsphere-proxy
(Maven)
Dec 22, 2022
Flarum mishandles invalidation of user email tokens
High
CVE-2019-11514
was published
for
flarum/flarum
(Composer)
May 24, 2022
Resource leakage when decoding certificates and keys
High
CVE-2022-1473
was published
for
openssl-src
(Rust)
May 4, 2022
Memory flaw in zeroize_derive
Critical
CVE-2021-45706
was published
for
zeroize_derive
(Rust)
Jan 6, 2022
ProTip!
Advisories are also available from the
GraphQL API