GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,562 advisories
Filter by severity
Keras: tar extraction permits symlink-based path traversal
Low
CVE-2026-12482
was published
for
keras
(pip)
Jul 14, 2026
Django: signed cookies are vulnerable to salt namespace collisions
Low
CVE-2026-6873
was published
for
django
(pip)
Jun 3, 2026
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
Low
CVE-2026-8404
was published
for
django
(pip)
Jun 3, 2026
Django: cache middleware may expose private responses when unrelated request cookies are present
Low
CVE-2026-48588
was published
for
django
(pip)
Jul 7, 2026
Django: has_vary_header may expose cached responses when Vary values contain whitespace
Low
CVE-2026-48587
was published
for
django
(pip)
Jun 3, 2026
Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
Low
CVE-2026-35193
was published
for
django
(pip)
Jun 3, 2026
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
Low
CVE-2026-71849
was published
for
hono
(npm)
Aug 7, 2026
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Low
CVE-2026-71847
was published
for
json
(RubyGems)
Aug 7, 2026
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
Low
CVE-2026-56394
was published
for
craftcms/cms
(Composer)
Jul 9, 2026
Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
Low
CVE-2026-56385
was published
for
craftcms/cms
(Composer)
Mar 26, 2026
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options
Low
CVE-2026-56393
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page
Low
CVE-2026-56381
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
Craft CMS: Incorrect path validation could potentially lead to path traversal
Low
GHSA-7hxc-f267-h5q7
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type
Low
CVE-2026-56383
was published
for
craftcms/cms
(Composer)
Feb 25, 2026
Mermaid configuration APIs allow prototype pollution
Low
CVE-2026-71438
was published
for
mermaid
(npm)
Aug 6, 2026
Contao: Possible path traversal in job download URIs
Low
CVE-2026-55825
was published
for
contao/contao
(Composer)
Aug 6, 2026
Contao crawler leaks auth credentials to external hosts
Low
CVE-2026-55824
was published
for
contao/contao
(Composer)
Aug 6, 2026
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Low
CVE-2026-71326
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
Low
CVE-2026-6733
was published
for
undici
(npm)
Jun 19, 2026
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
Low
GHSA-945v-v9p3-v5xw
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
Low
GHSA-gwfq-86j8-7qhv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
Electron: Cross-origin iframe can position native autofill popup
Low
CVE-2026-70600
was published
for
electron
(npm)
Aug 5, 2026
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
Low
CVE-2026-70598
was published
for
electron
(npm)
Aug 5, 2026
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Low
CVE-2026-70483
was published
for
open-webui
(pip)
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API