GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,865
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
25 advisories
Filter by severity
Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces...
Moderate
Unreviewed
CVE-2026-100868
was published
Sep 27, 2026
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
High
CVE-2026-59177
was published
for
esphome-device-builder
(pip)
Sep 9, 2026
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow...
Critical
Unreviewed
CVE-2026-20212
was published
Sep 2, 2026
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions...
Critical
Unreviewed
CVE-2026-82456
was published
Aug 29, 2026
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
High
CVE-2026-55641
was published
for
9router
(npm)
Aug 28, 2026
IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to...
Moderate
Unreviewed
CVE-2026-16713
was published
Aug 13, 2026
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of...
High
Unreviewed
CVE-2026-47873
was published
Jul 30, 2026
PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in
Critical
CVE-2026-57123
was published
for
praisonaiagents
(pip)
Jun 18, 2026
Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a...
Critical
Unreviewed
CVE-2026-0481
was published
May 15, 2026
gopls by default communicates via pipe. However, -port and -listen flags are supported as means...
High
Unreviewed
CVE-2026-42503
was published
May 6, 2026
OpenClaw: Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.0
High
GHSA-525j-hqq2-66r4
was published
for
openclaw
(npm)
Apr 17, 2026
Apache IoTDB has an Insecure Default Configuration Vulnerability
Critical
CVE-2026-24015
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Mar 9, 2026
OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback
Moderate
CVE-2026-28395
was published
for
openclaw
(npm)
Feb 17, 2026
Binding to an unrestricted ip address in Azure IoT SDK allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-21528
was published
Feb 10, 2026
Keycloak has debug default bind address
Moderate
CVE-2025-11538
was published
for
org.keycloak:keycloak-quarkus-dist
(Maven)
Dec 2, 2025
Duplicate Advisory: Keycloak allows Binding to an Unrestricted IP Address
Moderate
GHSA-7m9g-pmxf-m9m8
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 13, 2025
•
withdrawn
A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite...
Critical
Unreviewed
CVE-2025-61934
was published
Oct 24, 2025
Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code...
High
Unreviewed
CVE-2025-55322
was published
Sep 24, 2025
Excessive attack surface in acep-collector service due to binding to an unrestricted IP address....
Low
Unreviewed
CVE-2024-49384
was published
Oct 15, 2024
Excessive attack surface in archive-server service due to binding to an unrestricted IP address....
Low
Unreviewed
CVE-2024-49382
was published
Oct 15, 2024
Excessive attack surface in acep-importer service due to binding to an unrestricted IP address....
Low
Unreviewed
CVE-2024-49383
was published
Oct 15, 2024
dbt allows Binding to an Unrestricted IP Address via socketsocket
Moderate
CVE-2024-36105
was published
for
dbt-core
(pip)
May 28, 2024
Server receiving a malformed message based on a list of IPs resulting in heap corruption causing...
Moderate
Unreviewed
CVE-2023-5398
was published
Apr 17, 2024
Excessive attack surface due to binding to an unrestricted IP address. The following products are...
Moderate
Unreviewed
CVE-2023-41742
was published
Aug 31, 2023
Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an...
High
Unreviewed
CVE-2023-1968
was published
Apr 28, 2023
ProTip!
Advisories are also available from the
GraphQL API