GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
12,254 advisories
Filter by severity
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
High
CVE-2026-67422
was published
for
pymdown-extensions
(pip)
Aug 7, 2026
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
High
CVE-2026-63222
was published
for
codeigniter4/framework
(Composer)
Aug 7, 2026
jsii-diff: Command Injection via npm: package argument
High
CVE-2026-15895
was published
for
jsii-diff
(npm)
Aug 7, 2026
go-git: Worktree operations may follow symlinks
High
CVE-2026-71556
was published
for
github.com/go-git/go-git/v5
(Go)
Aug 7, 2026
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
High
GHSA-wvpp-8hx9-p66j
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
High
GHSA-jm78-9fvv-mhgr
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
High
GHSA-hmq2-w58f-27jc
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
High
GHSA-9rj7-rf2p-w77r
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
High
GHSA-4gmw-gg2m-w46p
was published
for
GitPython
(pip)
Aug 7, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
CVE-2026-67434
was published
for
squizlabs/php_codesniffer
(Composer)
Aug 6, 2026
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
High
GHSA-w9hm-4m3m-fxmm
was published
for
ngx-extended-pdf-viewer
(npm)
Aug 6, 2026
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
High
CVE-2026-16633
was published
for
pdfjs-dist
(npm)
Aug 6, 2026
Craft CMS: Arbitrary user password reset leading to administrator account takeover
High
GHSA-p8x7-9vfw-p7vc
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Authenticated RCE through Twig sandbox escape
High
GHSA-f5wm-88jv-g5hx
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
High
GHSA-265m-7826-wjqm
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via colliding heading slugs
High
GHSA-mh25-x5hq-wrqp
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via duplicate footnote definitions
High
GHSA-jfm3-95jq-q3rf
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via adjacent inline attribute blocks
High
GHSA-g2gp-3wwq-f4ph
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
High
CVE-2026-71488
was published
for
league/commonmark
(Composer)
Aug 6, 2026
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
High
GHSA-5p4m-2wfm-xmqj
was published
for
js-yaml
(npm)
Aug 6, 2026
Nx: Zip-Slip in the self-hosted remote cache
High
CVE-2026-71476
was published
for
@nx/azure-cache
(npm)
Aug 6, 2026
Statamic: Account takeover via OAuth email matching without email-verification check
High
CVE-2026-64665
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
High
CVE-2026-54763
was published
for
github.com/traefik/traefik/v2
(Go)
Aug 6, 2026
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
High
CVE-2026-67309
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
High
CVE-2026-71327
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
ProTip!
Advisories are also available from the
GraphQL API