GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,539 advisories
Filter by severity
carbon-apimgt does not properly restrict uploaded files
Critical
CVE-2025-13590
was published
for
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1
(Maven)
Feb 19, 2026
Jenkins GitHub Plugin has an XSS vulnerability
Critical
CVE-2026-42523
was published
for
com.coravy.hudson.plugins.github:github
(Maven)
Apr 29, 2026
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
Critical
CVE-2026-42027
was published
for
org.apache.opennlp:opennlp-tools
(Maven)
May 4, 2026
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
Critical
CVE-2026-53476
was published
for
github.com/kubev2v/assisted-migration-agent
(Go)
Jun 10, 2026
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
Critical
CVE-2026-53475
was published
for
github.com/kubev2v/assisted-migration-agent
(Go)
Jun 10, 2026
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
Critical
CVE-2026-53474
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
Critical
CVE-2026-53471
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
Critical
CVE-2026-53470
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
Critical
CVE-2026-39830
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Critical
GHSA-r277-6w6q-xmqw
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
Critical
CVE-2026-53469
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Critical
CVE-2026-64825
was published
for
homeassistant
(pip)
Jul 21, 2026
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
Critical
CVE-2026-53633
was published
for
@vitest/browser
(npm)
Jun 15, 2026
When Vitest UI server is listening, arbitrary file can be read and executed
Critical
CVE-2026-47429
was published
for
vitest
(npm)
Jun 1, 2026
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
Critical
CVE-2026-73653
was published
for
@vitest/browser
(npm)
Jul 21, 2026
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
Critical
CVE-2026-73649
was published
for
velocityjs
(npm)
Jul 24, 2026
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
CVE-2026-73644
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
Critical
CVE-2026-73567
was published
for
sm-crypto
(npm)
Jul 24, 2026
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
Critical
CVE-2026-52830
was published
for
fast-mcp-telegram
(pip)
Jul 2, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks
Critical
CVE-2026-52813
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Critical
CVE-2026-73421
was published
for
next-auth
(npm)
Jul 23, 2026
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Critical
CVE-2026-73420
was published
for
@auth/core
(npm)
Jul 23, 2026
Shescape: Shell injection via unescaped parentheses on Windows with CMD
Critical
CVE-2026-73414
was published
for
shescape
(npm)
Jul 24, 2026
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
Critical
CVE-2026-61459
was published
for
mcp-server-kubernetes
(pip)
Jul 10, 2026
Budibase has nonymous NoSQL operator injection via published-app query templates
Critical
CVE-2026-54350
was published
for
@budibase/server
(npm)
Jun 23, 2026
ProTip!
Advisories are also available from the
GraphQL API