GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
14,706 advisories
Filter by severity
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
Moderate
GHSA-652q-gvq3-74qv
was published
for
n8n
(npm)
Jul 22, 2026
n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
Moderate
GHSA-jqwr-vx3p-r266
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
Moderate
GHSA-9cmh-xcqm-5hqr
was published
for
n8n
(npm)
Jul 22, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Moderate
GHSA-89vp-jrxv-24w8
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Moderate
GHSA-h5v5-8746-g7mm
was published
for
jupyterlab
(pip)
Jul 22, 2026
Next.js: Cache confusion of response bodies for requests with bodies
Moderate
CVE-2026-64648
was published
for
next
(npm)
Jul 22, 2026
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Moderate
CVE-2026-64647
was published
for
next
(npm)
Jul 22, 2026
Next.js: Unbounded Server Action payload in Edge runtime
Moderate
CVE-2026-64646
was published
for
next
(npm)
Jul 22, 2026
Next.js: Denial of Service in the Image Optimization API using SVGs
Moderate
CVE-2026-64644
was published
for
next
(npm)
Jul 22, 2026
Next.js: Unauthenticated disclosure of internal Server Function endpoints
Moderate
CVE-2026-64643
was published
for
next
(npm)
Jul 22, 2026
Eclipse Jetty: Path parameter traversal
Moderate
CVE-2026-8384
was published
for
org.eclipse.jetty:jetty-util
(Maven)
Jul 22, 2026
Eclipse Jetty: HTTP Authority/Host mismatch
Moderate
CVE-2026-6790
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
Moderate
CVE-2026-10051
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Moderate
CVE-2026-65589
was published
for
n8n
(npm)
Jul 22, 2026
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
Moderate
CVE-2026-59943
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Moderate
CVE-2026-59942
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
Moderate
CVE-2026-59941
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
Moderate
CVE-2026-59820
was published
for
litellm
(pip)
Jul 22, 2026
n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
Moderate
CVE-2026-65014
was published
for
n8n
(npm)
Jul 22, 2026
n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
Moderate
CVE-2026-65596
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
Moderate
CVE-2026-65594
was published
for
n8n
(npm)
Jul 22, 2026
n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
Moderate
CVE-2026-65590
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
Moderate
CVE-2026-58661
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
Moderate
CVE-2026-59253
was published
for
n8n
(npm)
Jul 22, 2026
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
Moderate
CVE-2026-59254
was published
for
n8n
(npm)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API