GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
30,224 advisories
Filter by severity
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This...
Critical
Unreviewed
CVE-2026-42945
was published
May 13, 2026
vm2 Has a Sandbox Breakout Using Async Generator
Critical
CVE-2026-45411
was published
for
vm2
(npm)
May 14, 2026
FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
Critical
CVE-2026-46442
was published
for
flowise
(npm)
May 14, 2026
FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion
Critical
CVE-2026-44542
was published
for
github.com/gtsteffaniak/filebrowser
(Go)
May 7, 2026
Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
Critical
CVE-2026-42596
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users
Critical
CVE-2026-42555
was published
for
com.ritense.valtimo:case
(Maven)
May 6, 2026
Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection
Critical
CVE-2026-42589
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
MagicMirror vulnerable to unauthenticated SSRF via /cors endpoint
Critical
CVE-2026-42281
was published
for
magicmirror
(npm)
May 5, 2026
ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
Critical
CVE-2026-42601
was published
for
archivebox
(pip)
May 4, 2026
Compromise of PyTorch Lightning PyPi Package Versions
Critical
CVE-2026-44484
was published
for
pytorch-lightning
(pip)
May 7, 2026
Marten has an injection vulnerability in its full-text search regConfig parameter
Critical
CVE-2026-45288
was published
for
Marten
(NuGet)
May 14, 2026
@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Impersonation
Critical
GHSA-wf8q-wvv8-p8jf
was published
for
@samanhappy/mcphub
(npm)
May 14, 2026
misp-modules website - Missing CSRF protection in the website home blueprint
Critical
CVE-2026-44364
was published
for
misp-modules
(pip)
May 6, 2026
fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver
Critical
CVE-2026-44351
was published
for
fast-jwt
(npm)
May 6, 2026
vm2 has Sandbox Breakout Through Null Proto Exception
Critical
CVE-2026-44009
was published
for
vm2
(npm)
May 8, 2026
vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`
Critical
CVE-2026-44008
was published
for
vm2
(npm)
May 8, 2026
vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution
Critical
CVE-2026-44007
was published
for
vm2
(npm)
May 7, 2026
vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
Critical
CVE-2026-43999
was published
for
vm2
(npm)
May 7, 2026
vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape
Critical
CVE-2026-44005
was published
for
vm2
(npm)
May 7, 2026
vm2 Access to Host Object Enables Sandbox Escape
Critical
CVE-2026-43997
was published
for
vm2
(npm)
May 7, 2026
vm2 has a Sandbox Escape Vulnerability
Critical
CVE-2026-44006
was published
for
vm2
(npm)
May 7, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
Critical
CVE-2026-41050
was published
for
github.com/rancher/fleet
(Go)
May 7, 2026
Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass
Critical
CVE-2026-41574
was published
for
github.com/nhost/nhost
(Go)
Apr 18, 2026
Electerm Local code through electerm's single-instance socket
Critical
CVE-2026-45353
was published
for
electerm
(npm)
May 14, 2026
DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
Critical
CVE-2026-45374
was published
for
deepseek-tui
(Rust)
May 14, 2026
ProTip!
Advisories are also available from the
GraphQL API