GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,169
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
24 advisories
Filter by severity
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead...
High
Unreviewed
CVE-2026-48618
was published
Jun 26, 2026
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Moderate
CVE-2026-49401
was published
for
deno
(Rust)
Jun 16, 2026
SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts...
Critical
Unreviewed
CVE-2025-71316
was published
Jun 4, 2026
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
High
CVE-2026-45135
was published
for
github.com/caddyserver/caddy/v2
(Go)
May 18, 2026
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
High
CVE-2026-45062
was published
for
github.com/dunglas/frankenphp
(Go)
May 15, 2026
protobufjs has overlong UTF-8 decoding
Moderate
CVE-2026-44288
was published
for
@protobufjs/utf8
(npm)
May 12, 2026
uutils coreutils has an Improper Handling of Unicode Encoding Issue
Low
CVE-2026-35375
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Improper Handling of Unicode Encoding Issue
Low
CVE-2026-35373
was published
for
coreutils
(Rust)
Apr 22, 2026
coreutils' comm utility silently corrupts data by performing lossy UTF-8 conversion on all output lines
Low
CVE-2026-35346
was published
for
coreutils
(Rust)
Apr 22, 2026
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform...
Moderate
Unreviewed
CVE-2026-20202
was published
Apr 15, 2026
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote...
High
Unreviewed
CVE-2026-4116
was published
Apr 9, 2026
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote...
Moderate
Unreviewed
CVE-2026-4114
was published
Apr 9, 2026
OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists
Moderate
GHSA-392f-ggf5-fp3c
was published
for
openclaw
(npm)
Mar 2, 2026
Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
Moderate
CVE-2026-25480
was published
for
litestar
(pip)
Feb 9, 2026
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
High
CVE-2026-23950
was published
for
tar
(npm)
Jan 21, 2026
HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive...
Moderate
Unreviewed
CVE-2025-55129
was published
Dec 2, 2025
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path...
High
Unreviewed
CVE-2024-43093
was published
Nov 13, 2024
In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode ...
Moderate
Unreviewed
CVE-2024-8067
was published
Sep 25, 2024
Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side...
Unknown
Unreviewed
CVE-2017-20190
was published
Mar 27, 2024
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and...
Critical
Unreviewed
CVE-2024-24691
was published
Feb 14, 2024
ewen-lbh/ffcss Late-Unicode normalization vulnerability
Moderate
CVE-2023-52081
was published
for
github.com/ewen-lbh/ffcss
(Go)
Dec 28, 2023
An Improper Handling of Unicode Encoding vulnerability in the Schweitzer Engineering...
Moderate
Unreviewed
CVE-2023-31169
was published
Aug 31, 2023
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI...
Critical
Unreviewed
CVE-2023-39213
was published
Aug 9, 2023
Ciphertext Malleability Issue in Tink Java
Moderate
CVE-2020-8929
was published
for
com.google.crypto.tink:tink
(Maven)
Oct 16, 2020
ProTip!
Advisories are also available from the
GraphQL API