GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
68 advisories
Filter by severity
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
Moderate
GHSA-wchh-9x6h-7f6p
was published
for
matrix-commander
(pip)
Jul 29, 2026
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
High
GHSA-f88m-g3jw-g9cj
was published
for
sharp
(npm)
Jul 21, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs
High
GHSA-6vxv-wg6j-5qwp
was published
for
gogs.io/gogs
(Go)
Jun 19, 2026
OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL
High
GHSA-q7j3-v8qv-22vq
was published
for
github.com/opentofu/opentofu
(Go)
Jun 19, 2026
Vulnerable OpenSSL included in cryptography wheels
High
GHSA-537c-gmf6-5ccf
was published
for
cryptography
(pip)
Jun 15, 2026
Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering)
Moderate
GHSA-39h7-pwv7-rc3x
was published
for
@excalidraw/excalidraw
(npm)
Apr 24, 2026
OpenTofu has unbounded memory usage, high CPU usage, or deadlock in "tofu init" with maliciously-crafted dependency responses
Low
GHSA-hw5x-4r37-72w7
was published
for
github.com/opentofu/opentofu
(Go)
Apr 14, 2026
Axios supply chain attack - dependency in @lightdash/cli may resolve to compromised axios versions
Critical
GHSA-3hfp-gqgh-xc5g
was published
for
@lightdash/cli
(npm)
Apr 2, 2026
Axios npm Supply Chain Incident Impacting @usebruno/cli
Critical
CVE-2026-34841
was published
for
@usebruno/cli
(npm)
Apr 2, 2026
mcp-handler has a tool response leak across concurrent client sessions ('Race Condition')
High
GHSA-w2fm-25vw-vh7f
was published
for
mcp-handler
(npm)
Apr 1, 2026
EnhancedLinq.Async is Vulnerable to Denial of Service via Transitive Dependency Microsoft.Bcl.Memory
High
GHSA-32wq-ppwg-3w4m
was published
for
EnhancedLinq.Async
(NuGet)
Apr 1, 2026
Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
High
GHSA-46wh-3698-f2cx
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 29, 2026
Postiz App has a High-Severity SSRF Vulnerability via Next.js
High
GHSA-vj2p-7pgw-g2wf
was published
for
postiz
(npm)
Mar 27, 2026
C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)
High
GHSA-wcjx-v2wj-xg87
was published
for
c2cciutils
(pip)
Mar 26, 2026
splunk-otel-javaagent: Unsafe deserialization in RMI instrumentation may lead to Remote Code Execution
Critical
GHSA-h8w2-rv57-vc6f
was published
for
com.splunk:splunk-otel-javaagent
(Maven)
Mar 26, 2026
fido2-lib is vulnerable to DoS via cbor-extract heap buffer over-read in CBOR attestation parsing
High
GHSA-g3qj-j598-cxmq
was published
for
fido2-lib
(npm)
Mar 24, 2026
skia-python vendors vulnerable libfreetype because of pinned cibuildwheel version
High
GHSA-2mhw-8qcg-gr96
was published
for
skia-python
(pip)
Mar 19, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk
High
GHSA-q382-vc8q-7jhj
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Mar 19, 2026
Terraform Provider for ArgoCD has possible exposure to GO-2026-4337 / CVE-2025-68121
Moderate
GHSA-594f-3595-c47v
was published
for
github.com/argoproj-labs/terraform-provider-argocd
(Go)
Mar 18, 2026
Traefik affected by TLS ClientAuth Bypass on HTTP/3
High
GHSA-gv8r-9rw9-9697
was published
for
github.com/traefik/traefik
(Go)
Feb 20, 2026
Centrifugo v6.6.0 dependency vulnerabilities
Moderate
GHSA-j9wf-6r2x-hqmx
was published
for
github.com/centrifugal/centrifugo/v6
(Go)
Feb 19, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams
High
GHSA-26gq-grmh-6xm6
was published
for
gogs.io/gogs
(Go)
Feb 6, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images
Critical
GHSA-x9p2-77v6-6vhf
was published
for
github.com/dunglas/frankenphp
(Go)
Feb 5, 2026
OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format
Low
GHSA-r92c-9c7f-3pj8
was published
for
github.com/opentofu/opentofu
(Go)
Jan 21, 2026
Auth0 WordPress has Improper Audience Validation via Auth0-PHP SDK Dependency
Moderate
GHSA-vvg7-8rmq-92g7
was published
for
auth0/wordpress
(Composer)
Dec 17, 2025
ProTip!
Advisories are also available from the
GraphQL API