GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,513
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34,430 advisories
Filter by severity
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Moderate
CVE-2026-53708
was published
for
mcp-contextforge-gateway
(pip)
Aug 14, 2026
Jenkins GitHub Plugin has an XSS vulnerability
Critical
CVE-2026-42523
was published
for
com.coravy.hudson.plugins.github:github
(Maven)
Apr 29, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
Moderate
GHSA-8rw6-p7m8-63jp
was published
for
surrealdb
(Rust)
Aug 14, 2026
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
Critical
CVE-2026-42027
was published
for
org.apache.opennlp:opennlp-tools
(Maven)
May 4, 2026
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
High
CVE-2026-55153
was published
for
com.mchange:mchange-commons-java
(Maven)
Aug 14, 2026
OpenAM Insecure SSO Cookie Initialization
High
CVE-2026-53660
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Aug 14, 2026
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Moderate
CVE-2026-53658
was published
for
github.com/hyperledger/fabric-ca
(Go)
Aug 14, 2026
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
Grav: Unauthenticated denial of service via unbounded image derivative dimensions
High
CVE-2026-53653
was published
for
getgrav/grav
(Composer)
Aug 14, 2026
ldap3_proto has LDAP Filter stack exhaustion
High
GHSA-qcxq-75wr-5cm8
was published
for
ldap3_proto
(Rust)
May 6, 2026
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
Critical
CVE-2026-53476
was published
for
github.com/kubev2v/assisted-migration-agent
(Go)
Jun 10, 2026
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
Critical
CVE-2026-53475
was published
for
github.com/kubev2v/assisted-migration-agent
(Go)
Jun 10, 2026
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
Critical
CVE-2026-53474
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
High
CVE-2026-35219
was published
for
@budibase/server
(npm)
Aug 14, 2026
Directus has a DOM-Based cross-site scripting (XSS) via layout_options
Low
CVE-2024-6533
was published
for
directus
(npm)
Jan 23, 2025
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
Moderate
CVE-2026-53722
was published
for
nuxt
(npm)
Jun 16, 2026
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
Moderate
CVE-2026-56326
was published
for
nuxt
(npm)
Jun 16, 2026
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
High
CVE-2026-2332
was published
for
org.eclipse.jetty:jetty-http
(Maven)
Apr 14, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Moderate
CVE-2026-55590
was published
for
cakephp/authentication
(Composer)
Jun 17, 2026
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
Critical
CVE-2026-53471
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
Critical
CVE-2026-53470
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
High
CVE-2026-35511
was published
for
github.com/authorizerdev/authorizer
(Go)
Aug 14, 2026
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
High
CVE-2026-54513
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization
High
CVE-2026-13676
was published
for
fast-uri
(npm)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API