GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,153
Maven
5,000+
npm
5,000+
NuGet
861
pip
4,451
Pub
12
RubyGems
991
Rust
1,179
Swift
50
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
Apache IoTDB has an Insecure Default Configuration Vulnerability
Critical
CVE-2026-24015
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Mar 9, 2026
OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback
Moderate
CVE-2026-28395
was published
for
openclaw
(npm)
Feb 17, 2026
Binding to an unrestricted ip address in Azure IoT SDK allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-21528
was published
Feb 10, 2026
Keycloak has debug default bind address
Moderate
CVE-2025-11538
was published
for
org.keycloak:keycloak-quarkus-dist
(Maven)
Dec 2, 2025
Duplicate Advisory: Keycloak allows Binding to an Unrestricted IP Address
Moderate
GHSA-7m9g-pmxf-m9m8
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 13, 2025
•
withdrawn
A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite...
Critical
Unreviewed
CVE-2025-61934
was published
Oct 24, 2025
Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code...
High
Unreviewed
CVE-2025-55322
was published
Sep 24, 2025
Excessive attack surface in acep-importer service due to binding to an unrestricted IP address....
Low
Unreviewed
CVE-2024-49383
was published
Oct 15, 2024
Excessive attack surface in archive-server service due to binding to an unrestricted IP address....
Low
Unreviewed
CVE-2024-49382
was published
Oct 15, 2024
Excessive attack surface in acep-collector service due to binding to an unrestricted IP address....
Low
Unreviewed
CVE-2024-49384
was published
Oct 15, 2024
dbt allows Binding to an Unrestricted IP Address via socketsocket
Moderate
CVE-2024-36105
was published
for
dbt-core
(pip)
May 28, 2024
Server receiving a malformed message based on a list of IPs resulting in heap corruption causing...
Moderate
Unreviewed
CVE-2023-5398
was published
Apr 17, 2024
Excessive attack surface due to binding to an unrestricted IP address. The following products are...
Moderate
Unreviewed
CVE-2023-41742
was published
Aug 31, 2023
Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an...
High
Unreviewed
CVE-2023-1968
was published
Apr 28, 2023
ProTip!
Advisories are also available from the
GraphQL API