GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,426
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,670
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
Cosign's verify-blob-attestation reports false positive when payload parsing fails
Moderate
CVE-2026-39395
was published
for
github.com/sigstore/cosign
(Go)
Apr 8, 2026
File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
High
CVE-2026-35607
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check
Moderate
CVE-2026-35606
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
File Browser share links remain accessible after Share/Download permissions are revoked
High
CVE-2026-35604
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
File Browser has an access rule bypass via HasPrefix without trailing separator in path matching
Moderate
CVE-2026-35605
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags
High
GHSA-qmwh-9m9c-h36m
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 7, 2026
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri
High
GHSA-x3f4-v83f-7wp2
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)
High
CVE-2026-35464
was published
for
pyload-ng
(pip)
Apr 4, 2026
pyLoad: SSRF filter bypass via HTTP redirect in BaseDownloader (Incomplete fix for CVE-2026-33992)
Critical
CVE-2026-35459
was published
for
pyload-ng
(pip)
Apr 4, 2026
BentoML: Command Injection in cloud deployment setup script
High
CVE-2026-35043
was published
for
bentoml
(pip)
Apr 3, 2026
Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
Critical
CVE-2026-34976
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 2, 2026
StableLib Ed25519 Signature Malleability via Missing S < L Check
Moderate
GHSA-x3ff-w252-2g7j
was published
for
@stablelib/ed25519
(npm)
Apr 1, 2026
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
High
CVE-2026-34172
was published
for
giskard-agents
(pip)
Mar 27, 2026
AVideo has SSRF Protection Bypass via HTTP Redirect in Image Download Endpoints
Moderate
CVE-2026-33766
was published
for
wwbn/avideo
(Composer)
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API