GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
15,586 advisories
Filter by severity
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application...
Low
Unreviewed
CVE-2026-35142
was published
Jul 16, 2026
CVE-2026-40956
is a memory disclosure vulnerability in Secure Access client versions prior to 14...
Low
Unreviewed
CVE-2026-40956
was published
Jul 15, 2026
A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an...
Low
Unreviewed
CVE-2026-15474
was published
Jul 12, 2026
A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a...
Low
Unreviewed
CVE-2026-0276
was published
Jul 9, 2026
container: pf Rule Injection via Domain Name Argument in `container system dns create --localhost` Command
Low
GHSA-39g5-644c-qwcg
was published
for
github.com/apple/container
(Swift)
May 7, 2026
CVE-2026-40954
is an integer underflow vulnerability in the traffic parsing function of Secure...
Low
Unreviewed
CVE-2026-40954
was published
Jul 15, 2026
CVE-2026-40955 is an integer underflow
vulnerability in the traffic parsing function of Secure...
Low
Unreviewed
CVE-2026-40955
was published
Jul 15, 2026
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)
Low
CVE-2026-58196
was published
for
github.com/stacklok/toolhive
(Go)
Jul 15, 2026
bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV Map
Low
CVE-2026-11312
was published
for
infinistore
(pip)
Jun 5, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
Low
CVE-2026-50266
was published
for
neutron
(pip)
Jun 4, 2026
LMCache: 16-bit multimodal hash collision can poison KV cache entries
Low
CVE-2026-10813
was published
for
lmcache
(pip)
Jun 4, 2026
milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery
Low
CVE-2026-10814
was published
for
github.com/milvus-io/milvus
(Go)
Jun 4, 2026
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
Low
CVE-2026-54282
was published
for
Starlette
(pip)
Jun 15, 2026
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
Low
CVE-2026-53537
was published
for
python-multipart
(pip)
Jun 15, 2026
@babel/core: Arbitrary File Read via sourceMappingURL Comment
Low
CVE-2026-49356
was published
for
@babel/core
(npm)
Jun 15, 2026
Logback vulnerable to Object Injection through HardenedObjectInputStream modules
Low
CVE-2026-10532
was published
for
ch.qos.logback:logback-core
(Maven)
Jun 1, 2026
ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway
Low
CVE-2026-54450
was published
for
github.com/stacklok/toolhive
(Go)
Jul 15, 2026
AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
Low
CVE-2026-34520
was published
for
aiohttp
(pip)
Apr 1, 2026
opentelemetry-go's Schema ParseFile leaks file descriptors on each parse
Low
CVE-2026-45287
was published
for
go.opentelemetry.io/otel/schema
(Go)
May 28, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
CVE-2026-10804
was published
for
streamlit
(pip)
Jun 4, 2026
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
Low
CVE-2026-4874
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 26, 2026
GPTCache: File and image cache keys collide because BufferedReader.peek() only reads the buffered prefix
Low
CVE-2026-10812
was published
for
gptcache
(pip)
Jun 4, 2026
Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim
Low
CVE-2026-37977
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 6, 2026
MLflow: Deterministic sampling in dataset digest enables predictable collisions
Low
CVE-2026-10803
was published
for
mlflow
(pip)
Jun 4, 2026
Insertion of sensitive information into a file in the Recovery Kit response file generation...
Low
Unreviewed
CVE-2026-15642
was published
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API