GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,227
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,502
Pub
12
RubyGems
995
Rust
1,187
Swift
51
Unreviewed advisories
All unreviewed
5,000+
3,799 advisories
Filter by severity
FUXA Unauthenticated Remote Code Execution in Node-RED Integration
Critical
CVE-2026-25938
was published
for
fuxa-server
(npm)
Feb 10, 2026
@nyariv/sandboxjs has host prototype pollution from sandbox via array intermediary (sandbox escape)
Critical
CVE-2026-25881
was published
for
@nyariv/sandboxjs
(npm)
Feb 10, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure
Critical
CVE-2025-66630
was published
for
github.com/gofiber/fiber/v2
(Go)
Feb 9, 2026
Keylime Missing Authentication for Critical Function and Improper Authentication
Critical
CVE-2026-1709
was published
for
keylime
(pip)
Feb 6, 2026
Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper Authentication
Critical
GHSA-27jc-jmp8-qfw5
was published
for
keylime
(pip)
Feb 6, 2026
•
withdrawn
`uniswap-utils` was removed from crates.io for malicious code
Critical
GHSA-x468-phr8-h3p3
was published
for
uniswap-utils
(Rust)
Feb 6, 2026
`sha-rust` was removed from crates.io for malicious code
Critical
GHSA-3mmg-7c2q-8938
was published
for
sha-rust
(Rust)
Feb 6, 2026
`finch-rust` was removed from crates.io for malicious code
Critical
GHSA-f8h5-x737-x4xr
was published
for
finch-rust
(Rust)
Feb 6, 2026
`polymarket-clients-sdk` was removed from crates.io for malicious code
Critical
GHSA-382q-fpqh-29f7
was published
for
polymarket-clients-sdk
(Rust)
Feb 6, 2026
`evm-units` was removed from crates.io for malicious code
Critical
GHSA-6662-54xr-8423
was published
for
evm-units
(Rust)
Feb 6, 2026
A single post-release of dydx-v4-client contained obfuscated multi-stage loader
Critical
GHSA-4f84-67cv-qrv3
was published
for
dydx-v4-client
(pip)
Feb 6, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
Critical
CVE-2026-25592
was published
for
Microsoft.SemanticKernel.Core
(NuGet)
Feb 6, 2026
OpenSTAManager has an OS Command Injection in P7M File Processing
Critical
CVE-2025-69212
was published
for
devcode-it/openstamanager
(Composer)
Feb 6, 2026
Gogs's update .git/config file allows remote command execution
Critical
CVE-2025-64111
was published
for
gogs.io/gogs
(Go)
Feb 6, 2026
@nyariv/sandboxjs vulnerable to sandbox escape via TOCTOU bug on keys in property accesses
Critical
CVE-2026-25641
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
@nyariv/sandboxjs has a Sandbox Escape vulnerability
Critical
CVE-2026-25587
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
@nyariv/sandboxjs has Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollution
Critical
CVE-2026-25586
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
@payloadcms/drizzle has SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters
Critical
CVE-2026-25544
was published
for
@payloadcms/drizzle
(npm)
Feb 5, 2026
@nyariv/sandboxjs has a Sandbox Escape issue
Critical
CVE-2026-25520
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images
Critical
GHSA-x9p2-77v6-6vhf
was published
for
github.com/dunglas/frankenphp
(Go)
Feb 5, 2026
FUXA Unauthenticated Remote Arbitrary Device Tag Write
Critical
CVE-2026-25752
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
Critical
CVE-2026-25895
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration
Critical
CVE-2026-25894
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Exposure of Plaintext Database Credentials
Critical
CVE-2026-25751
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Remote Code Execution via Admin JWT Minting
Critical
CVE-2026-25893
was published
for
fuxa-server
(npm)
Feb 5, 2026
ProTip!
Advisories are also available from the
GraphQL API