GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,248
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,513
Pub
12
RubyGems
997
Rust
1,189
Swift
51
Unreviewed advisories
All unreviewed
5,000+
9,649 advisories
Filter by severity
Plane has SSRF via Incomplete IP Validation in Webhook URL Serializer
High
CVE-2026-30242
was published
for
plane
(pip)
Mar 5, 2026
@perfood/couch-auth has an Observable Timing Discrepancy
High
CVE-2025-70949
was published
for
@perfood/couch-auth
(npm)
Mar 5, 2026
Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
High
CVE-2026-3009
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 5, 2026
Keycloak SAML Broken has Authentication Bypass by Primary Weakness
High
CVE-2026-3047
was published
for
org.keycloak:keycloak-broker-saml
(Maven)
Mar 5, 2026
RAGAS has an Arbitrary File Read vulnerability
High
CVE-2025-45691
was published
for
ragas
(pip)
Mar 5, 2026
The Eclipse Jetty Server Artifact has a Gzip request memory leak
High
CVE-2026-1605
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Mar 5, 2026
Pingora vulnerable to cache poisoning via insecure-by-default cache key
High
CVE-2026-2836
was published
for
pingora-cache
(Rust)
Mar 5, 2026
OliveTin has JWT Audience Validation Bypass in Local Key and HMAC Modes
High
CVE-2026-30223
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
Gogs: DOM-based XSS via milestone selection
High
CVE-2026-26276
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gogs: Release tag option injection in release deletion
High
CVE-2026-26194
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gogs: Stored XSS via data URI in issue comments
High
CVE-2026-26022
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gokapi has Stored XSS in SVG Hotlinks
High
CVE-2026-28683
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
xgrammar vulnerable to DoS via multi-layer nesting
High
CVE-2026-25048
was published
for
xgrammar
(pip)
Mar 5, 2026
AVideo: Unauthenticated PHP session store exposed to host network via published memcached port
High
CVE-2026-29093
was published
for
wwbn/avideo
(Composer)
Mar 5, 2026
opennextjs-cloudflare has SSRF vulnerability via /cdn-cgi/ path normalization bypass
High
CVE-2026-3125
was published
for
@opennextjs/cloudflare
(npm)
Mar 5, 2026
tar has Hardlink Path Traversal via Drive-Relative Linkpath
High
CVE-2026-29786
was published
for
tar
(npm)
Mar 5, 2026
Ghost has incomplete CSRF protections around OTC use
High
CVE-2026-29784
was published
for
ghost
(npm)
Mar 5, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
High
GHSA-hhjv-jq77-cmvx
was published
for
zeptoclaw
(Rust)
Mar 5, 2026
Parse Server's Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction
High
CVE-2026-29182
was published
for
parse-server
(npm)
Mar 5, 2026
pyLoad has an Arbitrary File Write via Path Traversal in edit_package()
High
CVE-2026-29778
was published
for
pyload-ng
(pip)
Mar 5, 2026
Duplicate Advisory: Cache poisoning via insecure-by-default cache key
High
GHSA-2m8c-2374-465f
was published
for
pingora-cache
(Rust)
Mar 5, 2026
•
withdrawn
Multer Vulnerable to Denial of Service via Uncontrolled Recursion
High
CVE-2026-3520
was published
for
multer
(npm)
Mar 5, 2026
TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution
High
CVE-2026-29186
was published
for
@backstage/plugin-techdocs-node
(npm)
Mar 5, 2026
Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege Escalation on Windows
High
CVE-2025-15558
was published
for
github.com/docker/cli
(Go)
Mar 5, 2026
SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)
High
CVE-2026-29074
was published
for
svgo
(npm)
Mar 4, 2026
ProTip!
Advisories are also available from the
GraphQL API