GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
2,185 advisories
Filter by severity
uutils coreutils has an Improper Handling of Unicode Encoding Issue
Low
CVE-2026-35373
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Improper Handling of Unicode Encoding Issue
Low
CVE-2026-35375
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Incorrect Short Circuit Evaluation Issue
Low
CVE-2026-35378
was published
for
coreutils
(Rust)
Apr 22, 2026
coreutils' comm utility silently corrupts data by performing lossy UTF-8 conversion on all output lines
Low
CVE-2026-35346
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
Low
CVE-2026-35353
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
Low
CVE-2026-35362
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Improper Preservation of Permissions issue
Low
CVE-2026-35361
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Incorrect Permission Assignment for Critical Resource
Low
CVE-2026-35367
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Unchecked Return Value Issue
Low
CVE-2026-35344
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Issue With its Always-Incorrect Control Flow Implementation
Low
CVE-2026-35343
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils' mktemp utility doesn't properly handle an empty TMPDIR environment variable
Low
CVE-2026-35342
was published
for
coreutils
(Rust)
Apr 22, 2026
Poetry has Path Traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
Low
CVE-2026-41140
was published
for
poetry
(pip)
Apr 22, 2026
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
Low
CVE-2026-22746
was published
for
org.springframework.security:spring-security-core
(Maven)
Apr 22, 2026
Bagisto affected by Server-Side Request Forgery
Low
CVE-2026-6744
was published
for
bagisto/bagisto
(Composer)
Apr 21, 2026
Bagisto affected by Cross-site Scripting
Low
CVE-2026-6745
was published
for
bagisto/bagisto
(Composer)
Apr 21, 2026
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
Low
CVE-2026-40264
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
Low
CVE-2026-39396
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
Low
CVE-2026-39388
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
October CMS: Editor Sub-Permission Bypass for Asset and Blueprint File Operations
Low
CVE-2026-29179
was published
for
october/system
(Composer)
Apr 21, 2026
October CMS: Reflected XSS via DataTable Form Widget
Low
CVE-2026-27937
was published
for
october/system
(Composer)
Apr 21, 2026
Memos has an Incorrect Privilege Assignment issue
Low
CVE-2026-6634
was published
for
github.com/usememos/memos
(Go)
Apr 20, 2026
Cockpit has NoSQL Injection Through Content Aggregation Pipelines
Low
CVE-2026-6626
was published
for
cockpit-hq/cockpit
(Composer)
Apr 20, 2026
Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
Low
CVE-2026-6598
was published
for
langflow
(pip)
Apr 20, 2026
Langflow has an Information Leak through Incomplete API Key Redaction
Low
CVE-2026-6597
was published
for
langflow
(pip)
Apr 20, 2026
ProTip!
Advisories are also available from the
GraphQL API