GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
98 advisories
Filter by severity
Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound Filtering
Critical
CVE-2026-47323
was published
for
org.apache.camel:camel-cxf-rest
(Maven)
May 19, 2026
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
High
CVE-2026-45135
was published
for
github.com/caddyserver/caddy/v2
(Go)
May 18, 2026
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
High
CVE-2026-45062
was published
for
github.com/dunglas/frankenphp
(Go)
May 15, 2026
Apache Tomcat: LockOutRealm treats user names as case-sensitive
High
CVE-2026-43513
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 12, 2026
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive...
Moderate
Unreviewed
CVE-2026-3833
was published
Apr 30, 2026
Apache Camel has an incomplete fix for CVE-2025-27636
Critical
CVE-2026-40453
was published
for
org.apache.camel:camel-coap
(Maven)
Apr 27, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass
High
CVE-2026-42273
was published
for
github.com/dadrus/heimdall
(Go)
Apr 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation
High
CVE-2026-42272
was published
for
github.com/dadrus/heimdall
(Go)
Apr 25, 2026
Multiple security fixes in justhtml
Low
GHSA-4p64-v8f5-r2gx
was published
for
justhtml
(pip)
Apr 14, 2026
justhtml includes multiple security fixes
Moderate
GHSA-c9vm-hv86-f23r
was published
for
justhtml
(pip)
Apr 10, 2026
Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags
High
GHSA-qmwh-9m9c-h36m
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 7, 2026
OpenClaw: Windows-compatible env override keys could bypass system.run approval binding
Moderate
GHSA-98ch-45wp-ch47
was published
for
openclaw
(npm)
Apr 7, 2026
prompts.chat prior to commit 1464475 contains an identity confusion vulnerability due to...
High
Unreviewed
CVE-2026-22665
was published
Apr 3, 2026
Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client...
Moderate
Unreviewed
CVE-2026-3532
was published
Mar 26, 2026
OpenClaw: Exec approval allowlist patterns overmatched on POSIX paths
Moderate
GHSA-f8r2-vg7x-gh8m
was published
for
openclaw
(npm)
Mar 13, 2026
simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE
Critical
CVE-2026-28292
was published
for
simple-git
(npm)
Mar 10, 2026
traefik CVE-2024-45410 fix bypass: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)
High
CVE-2026-29054
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 4, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity
High
CVE-2026-27896
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Feb 26, 2026
Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass
High
CVE-2026-27588
was published
for
github.com/caddyserver/caddy/v2
(Go)
Feb 24, 2026
Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypass
High
CVE-2026-27587
was published
for
github.com/caddyserver/caddy/v2
(Go)
Feb 24, 2026
File Browser has an Authentication Bypass in User Password Update
Moderate
CVE-2026-25889
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Feb 10, 2026
SiYuan File Read API Case Sensitivity Bypass can Lead to Path Traversal
High
CVE-2026-25992
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jan 28, 2026
Formio improperly authorized permission elevation through specially crafted request path
High
CVE-2025-67718
was published
for
formio
(npm)
Dec 10, 2025
elysia-cors Origin Validation Error
Moderate
CVE-2025-50864
was published
for
@elysiajs/cors
(npm)
Aug 20, 2025
Apache Tomcat - CGI security constraint bypass
Low
CVE-2025-46701
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 29, 2025
ProTip!
Advisories are also available from the
GraphQL API