GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,562 advisories
Filter by severity
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
Low
CVE-2026-71849
was published
for
hono
(npm)
Aug 7, 2026
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Low
CVE-2026-71847
was published
for
json
(RubyGems)
Aug 7, 2026
Craft CMS: Incorrect path validation could potentially lead to path traversal
Low
GHSA-7hxc-f267-h5q7
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Mermaid configuration APIs allow prototype pollution
Low
CVE-2026-71438
was published
for
mermaid
(npm)
Aug 6, 2026
Contao: Possible path traversal in job download URIs
Low
CVE-2026-55825
was published
for
contao/contao
(Composer)
Aug 6, 2026
Contao crawler leaks auth credentials to external hosts
Low
CVE-2026-55824
was published
for
contao/contao
(Composer)
Aug 6, 2026
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Low
CVE-2026-71326
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
Low
GHSA-945v-v9p3-v5xw
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
Low
GHSA-gwfq-86j8-7qhv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
Electron: Cross-origin iframe can position native autofill popup
Low
CVE-2026-70600
was published
for
electron
(npm)
Aug 5, 2026
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
Low
CVE-2026-70598
was published
for
electron
(npm)
Aug 5, 2026
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Low
CVE-2026-70483
was published
for
open-webui
(pip)
Aug 4, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
Low
CVE-2026-54787
was published
for
github.com/sigstore/sigstore-go
(Go)
Jul 31, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Low
CVE-2026-53607
was published
for
apostrophe
(npm)
Jul 31, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
CVE-2026-54522
was published
for
msgpack
(RubyGems)
Jul 30, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
GHSA-pmwx-rm49-xv39
was published
for
activerecord-tenanted
(RubyGems)
Jul 29, 2026
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
Low
CVE-2026-52838
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
Low
CVE-2026-52841
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Low
CVE-2026-52839
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Low
CVE-2026-52840
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
Low
GHSA-pc2w-4mq8-32qw
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 29, 2026
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
Low
CVE-2026-55403
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
Low
CVE-2026-50568
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
CVE-2026-54620
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API