GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
101 advisories
Filter by severity
Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to...
Moderate
Unreviewed
CVE-2026-63771
was published
Jul 20, 2026
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')...
Low
Unreviewed
CVE-2025-62675
was published
Jul 14, 2026
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')...
Low
Unreviewed
CVE-2025-62826
was published
Jul 14, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
Moderate
CVE-2026-54163
was published
for
secure_headers
(RubyGems)
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
CVE-2026-48596
was published
for
tesla
(Erlang)
Jul 10, 2026
Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is...
Moderate
Unreviewed
CVE-2025-71381
was published
Jul 1, 2026
Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(),...
Moderate
Unreviewed
CVE-2026-56762
was published
Jun 23, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
Moderate
CVE-2026-55766
was published
for
guzzlehttp/psr7
(Composer)
Jun 19, 2026
Kirby: Request header injection in `Http\Remote`
Moderate
CVE-2026-50188
was published
for
getkirby/cms
(Composer)
Jun 18, 2026
aiohttp: CRLF injection in multipart headers
Low
CVE-2026-50269
was published
for
aiohttp
(pip)
Jun 15, 2026
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing...
Moderate
Unreviewed
CVE-2026-50630
was published
Jun 12, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
Moderate
CVE-2026-49214
was published
for
guzzlehttp/psr7
(Composer)
Jun 11, 2026
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')...
Moderate
Unreviewed
CVE-2026-43966
was published
Jun 8, 2026
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
Moderate
CVE-2026-47675
was published
for
hono
(npm)
Jun 4, 2026
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated...
Critical
Unreviewed
CVE-2026-38967
was published
Jun 2, 2026
transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI...
Moderate
Unreviewed
CVE-2026-38978
was published
Jun 2, 2026
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
Low
CVE-2026-44489
was published
for
axios
(npm)
May 29, 2026
Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header...
High
Unreviewed
CVE-2026-9658
was published
May 28, 2026
HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control...
Moderate
Unreviewed
CVE-2026-7010
was published
May 12, 2026
eventsource-encoder vulnerable to SSE event injection via unsanitized `event` and `id` fields
Moderate
CVE-2026-44214
was published
for
eventsource-encoder
(npm)
May 8, 2026
Netty has HTTP Header Injection via HttpProxyHandler Disabled Validation (Incomplete Fix CVE-2025-67735)
Low
CVE-2026-42578
was published
for
io.netty:netty-handler-proxy
(Maven)
May 7, 2026
Microdot has HTTP response splitting in Response.set_cookie()
Low
CVE-2026-42874
was published
for
microdot
(pip)
May 5, 2026
Axios: Header Injection via Prototype Pollution
High
CVE-2026-42035
was published
for
axios
(npm)
May 5, 2026
i18next-http-middleware: HTTP response splitting and DoS via unsanitised Content-Language header
High
CVE-2026-41683
was published
for
i18next-http-middleware
(npm)
Apr 22, 2026
Serendipity has a Host Header Injection allows SMTP header injection via unvalidated HTTP_HOST in Message-ID email header
High
CVE-2026-39971
was published
for
s9y/serendipity
(Composer)
Apr 14, 2026
ProTip!
Advisories are also available from the
GraphQL API