GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
764 advisories
Filter by severity
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
Moderate
GHSA-h4mf-4v27-hggj
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
Moderate
GHSA-8mxv-9xhp-86h4
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could...
Moderate
Unreviewed
CVE-2026-20294
was published
Aug 5, 2026
This issue was addressed by using HTTPS when sending information over the network. This issue is...
Moderate
Unreviewed
CVE-2026-64742
was published
Jul 27, 2026
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext...
Moderate
Unreviewed
CVE-2026-3182
was published
Jul 21, 2026
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock...
Moderate
Unreviewed
CVE-2026-34346
was published
Jul 14, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
Moderate
CVE-2026-53624
was published
for
github.com/gofiber/fiber
(Go)
Jul 6, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
High
CVE-2026-50200
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Jul 2, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
CVE-2026-48978
was published
for
oras.land/oras-go
(Go)
Jul 1, 2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could...
Moderate
Unreviewed
CVE-2025-36336
was published
Jun 30, 2026
IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch-1 transmits data in clear...
Moderate
Unreviewed
CVE-2025-12530
was published
Jun 30, 2026
The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection...
High
Unreviewed
CVE-2026-49486
was published
Jun 26, 2026
Overview:
A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return...
High
Unreviewed
CVE-2026-11833
was published
Jun 23, 2026
guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
Moderate
CVE-2026-55568
was published
for
guzzlehttp/guzzle
(Composer)
Jun 19, 2026
An attacker within BLE communication range can passively intercept
wireless traffic and obtain...
High
Unreviewed
CVE-2026-50034
was published
Jun 19, 2026
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
Moderate
CVE-2026-48022
was published
for
@hapi/wreck
(npm)
Jun 11, 2026
A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable...
High
Unreviewed
CVE-2026-9741
was published
Jun 10, 2026
This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in...
High
Unreviewed
CVE-2026-45432
was published
Jun 4, 2026
Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert...
High
Unreviewed
CVE-2026-8874
was published
Jun 3, 2026
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over...
Moderate
Unreviewed
CVE-2026-36610
was published
Jun 3, 2026
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
Low
CVE-2026-7666
was published
for
django
(pip)
Jun 3, 2026
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client...
Moderate
Unreviewed
CVE-2023-52951
was published
Jun 3, 2026
CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network...
High
Unreviewed
CVE-2026-43625
was published
Jun 1, 2026
stigmem-node's federation insecure transport settings may allow non-loopback cleartext federation
Critical
GHSA-jmfc-hfjq-pxcp
was published
for
stigmem-node
(pip)
May 29, 2026
ProTip!
Advisories are also available from the
GraphQL API