GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
17 advisories
Filter by severity
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
Moderate
CVE-2026-85709
was published
for
lightrag-hku
(pip)
Sep 22, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
CVE-2026-75911
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
High
CVE-2026-75859
was published
for
codewhale
(npm)
Sep 4, 2026
VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root
Moderate
CVE-2026-61625
was published
for
github.com/VictoriaMetrics/VictoriaMetrics
(Go)
Sep 3, 2026
elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections
Moderate
CVE-2026-81890
was published
for
studio-42/elfinder
(Composer)
Sep 2, 2026
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Moderate
CVE-2026-49447
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
High
CVE-2026-55578
was published
for
pheditor/pheditor
(Composer)
Jul 16, 2026
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens
Moderate
CVE-2026-55513
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting
Moderate
CVE-2026-55512
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
Moderate
CVE-2026-53624
was published
for
github.com/gofiber/fiber
(Go)
Jul 6, 2026
Mautic Focus component Vulnerable to SSRF
Moderate
CVE-2026-9557
was published
for
mautic/core
(Composer)
Jul 2, 2026
Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
High
CVE-2026-53925
was published
for
glances
(pip)
Jun 23, 2026
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
High
CVE-2026-55660
was published
for
@tinacms/app
(npm)
Jun 19, 2026
ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components
Low
CVE-2026-55671
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
Moderate
GHSA-268h-hp4c-crq3
was published
for
nodemailer
(npm)
Jun 15, 2026
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
Moderate
GHSA-wqvq-jvpq-h66f
was published
for
nodemailer
(npm)
Jun 15, 2026
Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
High
GHSA-gv7w-rqvm-qjhr
was published
for
esbuild
(npm)
Jun 12, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API