GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
12,254 advisories
Filter by severity
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
High
GHSA-88pr-878c-24wf
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
High
CVE-2026-70471
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
High
CVE-2026-69263
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
High
CVE-2026-69262
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
High
CVE-2026-69258
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
High
CVE-2026-69257
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
High
CVE-2026-69252
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
High
CVE-2026-69250
was published
for
flowise
(npm)
Aug 4, 2026
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
High
CVE-2026-69249
was published
for
cryptography
(pip)
Aug 3, 2026
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
High
CVE-2026-69247
was published
for
cryptography
(pip)
Aug 3, 2026
Guzzle: Noncanonical host can bypass host-based checks
High
CVE-2026-69246
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
High
CVE-2026-69244
was published
for
aiohttp
(pip)
Aug 3, 2026
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
High
GHSA-3f7w-8rr8-f37f
was published
for
GitPython
(pip)
Aug 3, 2026
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
High
CVE-2026-69192
was published
for
ip-address
(npm)
Aug 3, 2026
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
High
CVE-2026-13697
was published
for
undici
(npm)
Aug 3, 2026
fast-uri vulnerable to host confusion via backslash authority introducer
High
CVE-2026-18446
was published
for
fast-uri
(npm)
Aug 3, 2026
Socket.IO: Zero-attachment Memory Exhaustion
High
CVE-2026-69185
was published
for
socket.io-parser
(npm)
Aug 3, 2026
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
High
CVE-2026-69152
was published
for
brace-expansion
(npm)
Aug 3, 2026
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
High
CVE-2026-69151
was published
for
@angular/compiler
(npm)
Aug 3, 2026
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)
High
CVE-2026-69149
was published
for
@angular/platform-server
(npm)
Aug 3, 2026
Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
High
CVE-2026-68945
was published
for
@angular/common
(npm)
Aug 3, 2026
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
High
GHSA-mqq9-gxg5-m58g
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
High
GHSA-mjrx-74jh-7xgw
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
High
GHSA-7qf5-7ppr-87v8
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 1, 2026
•
withdrawn
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
High
CVE-2026-54910
was published
for
github.com/gtsteffaniak/filebrowser/backend
(Go)
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API