GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
917 advisories
Filter by severity
carbon-apimgt does not properly restrict uploaded files
Critical
CVE-2025-13590
was published
for
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1
(Maven)
Feb 19, 2026
Jenkins GitHub Plugin has an XSS vulnerability
Critical
CVE-2026-42523
was published
for
com.coravy.hudson.plugins.github:github
(Maven)
Apr 29, 2026
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
Critical
CVE-2026-42027
was published
for
org.apache.opennlp:opennlp-tools
(Maven)
May 4, 2026
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
CVE-2026-73644
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
fastjson has a remote code execution (RCE) vulnerability
Critical
CVE-2026-16723
was published
for
com.alibaba:fastjson
(Maven)
Jul 23, 2026
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
Critical
CVE-2026-62379
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Jul 24, 2026
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
Critical
CVE-2026-44221
was published
for
com.arcadedb:arcadedb-server
(Maven)
May 5, 2026
jinjava has Sandbox Bypass via JavaType-Based Deserialization
Critical
CVE-2025-59340
was published
for
com.hubspot.jinjava:jinjava
(Maven)
Sep 17, 2025
OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution
Critical
CVE-2026-33701
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Mar 25, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Critical
GHSA-68r5-9hpg-7qw9
was published
for
org.openidentityplatform.opendj:opendj-dsml-servlet
(Maven)
Jul 24, 2026
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
Critical
CVE-2026-62263
was published
for
org.openidentityplatform.openam:openam-auth-webauthn
(Maven)
Jul 24, 2026
Apache Camel: camel-mongodb-gridfs producer allows GridFS operation override and NoSQL operator injection via unfiltered gridfs.* HTTP headers
Critical
CVE-2026-48204
was published
for
org.apache.camel:camel-mongodb-gridfs
(Maven)
Jul 6, 2026
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF)
Critical
CVE-2026-48205
was published
for
org.apache.camel:camel-dns
(Maven)
Jul 6, 2026
Apache Camel: KeycloakSecurityPolicy has Improper Authentication, Missing Authentication for Critical Function and Failing Open Vulnerabilities
Critical
CVE-2026-53913
was published
for
org.apache.camel:camel-keycloak
(Maven)
Jul 6, 2026
Apache Fory Java SDK Has Deserialization of Untrusted Data in the Java replace-resolve path
Critical
CVE-2026-50076
was published
for
org.apache.fory:fory-core
(Maven)
Jun 4, 2026
Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass
Critical
CVE-2026-47065
was published
for
org.apache.mina:mina-core
(Maven)
Jun 3, 2026
Apache Derby: LDAP injection vulnerability in authenticator
Critical
CVE-2022-46337
was published
for
org.apache.derby:derby
(Maven)
Nov 20, 2023
Deserialization of Untrusted Data in Jython
Critical
CVE-2016-4000
was published
for
org.python:jython
(Maven)
May 13, 2022
LaunchServer FileServerHandler has an unauthenticated path traversal issue
Critical
CVE-2026-54617
was published
for
pro.gravit.launcher:launchserver-api
(Maven)
Jul 2, 2026
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
Critical
CVE-2026-57168
was published
for
io.openremote:openremote-manager
(Maven)
Jun 19, 2026
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
Critical
CVE-2025-14813
was published
for
org.bouncycastle:bcprov-debug-jdk14
(Maven)
Apr 17, 2026
Opendaylight will authenticate any username and password combination
Critical
CVE-2015-1778
was published
for
org.opendaylight.odlparent:opendaylight-karaf-resources
(Maven)
May 17, 2022
Apache CXF has an LDAP injection vulnerability
Critical
CVE-2026-44930
was published
for
org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap
(Maven)
May 26, 2026
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints
Critical
CVE-2026-45052
was published
for
org.openidentityplatform.openam:openam-federation-library
(Maven)
Jun 24, 2026
OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage
Critical
CVE-2026-45051
was published
for
org.openidentityplatform.openam:openam-auth-webauthn
(Maven)
Jun 24, 2026
ProTip!
Advisories are also available from the
GraphQL API