GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
12,303 advisories
Filter by severity
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
High
CVE-2026-55157
was published
for
@ooples/token-optimizer-mcp
(npm)
Aug 14, 2026
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
High
CVE-2026-55153
was published
for
com.mchange:mchange-commons-java
(Maven)
Aug 14, 2026
OpenAM Insecure SSO Cookie Initialization
High
CVE-2026-53660
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Aug 14, 2026
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
Grav: Unauthenticated denial of service via unbounded image derivative dimensions
High
CVE-2026-53653
was published
for
getgrav/grav
(Composer)
Aug 14, 2026
ldap3_proto has LDAP Filter stack exhaustion
High
GHSA-qcxq-75wr-5cm8
was published
for
ldap3_proto
(Rust)
May 6, 2026
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
High
CVE-2026-35219
was published
for
@budibase/server
(npm)
Aug 14, 2026
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
High
CVE-2026-2332
was published
for
org.eclipse.jetty:jetty-http
(Maven)
Apr 14, 2026
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
High
CVE-2026-35511
was published
for
github.com/authorizerdev/authorizer
(Go)
Aug 14, 2026
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
High
CVE-2026-54513
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization
High
CVE-2026-13676
was published
for
fast-uri
(npm)
Jul 21, 2026
pyasn1 has a DoS vulnerability in decoder
High
CVE-2026-23490
was published
for
pyasn1
(pip)
Jan 16, 2026
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
High
CVE-2026-73654
was published
for
@trigger.dev/core
(npm)
Aug 13, 2026
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
High
CVE-2026-12243
was published
for
nltk
(pip)
Aug 13, 2026
Duplicate Advisory: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
High
GHSA-q5h6-fcf5-49g9
was published
for
nltk
(pip)
Jun 30, 2026
•
withdrawn
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
High
CVE-2026-73418
was published
for
@auth/core
(npm)
Jul 23, 2026
Genql: inject arbitrary JavaScript or TypeScript via a GraphQL schema
High
CVE-2026-63397
was published
for
@genql/cli
(npm)
Jul 16, 2026
Laravel-Mediable: path traversal vulnerability in the File::sanitizePath()
High
CVE-2026-49970
was published
for
plank/laravel-mediable
(Composer)
Jul 13, 2026
MLflow: trace API endpoints lack proper authorization validators
High
CVE-2026-8147
was published
for
mlflow
(pip)
Jul 2, 2026
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
High
CVE-2026-54428
was published
for
org.apache.httpcomponents.core5:httpcore5-h2
(Maven)
Jul 1, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries
High
GHSA-fp43-vj7g-pg92
was published
for
org.omnifaces:omnifaces
(Maven)
Jul 24, 2026
Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation
High
CVE-2026-53435
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
High
CVE-2026-73652
was published
for
vantage6
(pip)
Jul 24, 2026
SVGO removeScripts plugin leaves some executable scripts intact
High
CVE-2026-73650
was published
for
svgo
(npm)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API