GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,575 advisories
Filter by severity
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when...
Critical
Unreviewed
CVE-2026-77179
was published
Sep 15, 2026
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Golden...
High
Unreviewed
CVE-2026-84584
was published
Sep 14, 2026
In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable...
High
Unreviewed
CVE-2026-82049
was published
Sep 14, 2026
A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function...
Low
Unreviewed
CVE-2026-90807
was published
Sep 14, 2026
File Browser through 2.63.23 applies path rules to the requested lexical path but resolves...
High
Unreviewed
CVE-2026-90930
was published
Sep 14, 2026
Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in...
Critical
Unreviewed
CVE-2026-89258
was published
Sep 11, 2026
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
Moderate
CVE-2026-88016
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
A flaw was found in crun. When the container configuration does not give /dev a dedicated mount,...
Moderate
Unreviewed
CVE-2026-88264
was published
Sep 10, 2026
A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink...
Moderate
Unreviewed
CVE-2026-88265
was published
Sep 10, 2026
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a...
Moderate
Unreviewed
CVE-2026-78622
was published
Sep 8, 2026
Improper link resolution before file access ('link following') in Windows Resilient File System ...
High
Unreviewed
CVE-2026-83999
was published
Sep 8, 2026
Improper link resolution before file access ('link following') in Windows Update Stack allows an...
High
Unreviewed
CVE-2026-81963
was published
Sep 8, 2026
Improper link resolution before file access ('link following') in Windows Shell allows an...
High
Unreviewed
CVE-2026-70563
was published
Sep 8, 2026
Improper link resolution before file access ('link following') in Windows Container Manager...
Moderate
Unreviewed
CVE-2026-69771
was published
Sep 8, 2026
Improper link resolution before file access ('link following') in Windows NTFS allows an...
Moderate
Unreviewed
CVE-2026-69425
was published
Sep 8, 2026
Improper link resolution before file access ('link following') in Windows NTFS allows an...
High
Unreviewed
CVE-2026-69379
was published
Sep 8, 2026
Improper link resolution before file access ('link following') in Windows Setup Files Cleanup...
High
Unreviewed
CVE-2026-69289
was published
Sep 8, 2026
Improper link resolution before file access ('link following') in Windows Universal Plug and Play...
Moderate
Unreviewed
CVE-2026-68830
was published
Sep 8, 2026
Improper link resolution before file access ('link following') in SQL Server allows an authorized...
High
Unreviewed
CVE-2026-67368
was published
Sep 8, 2026
Infracost: Arbitrary file read via config-template readFile symlink traversal
Moderate
CVE-2026-71493
was published
for
github.com/infracost/infracost
(Go)
Sep 8, 2026
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
High
CVE-2026-79676
was published
for
nltk
(pip)
Sep 8, 2026
NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
Moderate
CVE-2026-62383
was published
for
nltk
(pip)
Sep 8, 2026
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
High
CVE-2026-62384
was published
for
nltk
(pip)
Sep 8, 2026
NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root
High
CVE-2026-70626
was published
for
nltk
(pip)
Sep 8, 2026
A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION...
Moderate
Unreviewed
CVE-2026-86469
was published
Sep 7, 2026
ProTip!
Advisories are also available from the
GraphQL API