GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
35 advisories
Filter by severity
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Moderate
GHSA-89vp-jrxv-24w8
was published
for
jupyterlab
(pip)
Jul 22, 2026
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive...
Moderate
Unreviewed
CVE-2026-3833
was published
Apr 30, 2026
MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
Moderate
CVE-2026-57441
was published
for
@bitbonsai/mcpvault
(npm)
Jun 18, 2026
A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to...
Moderate
Unreviewed
CVE-2025-4035
was published
Apr 29, 2025
@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
Moderate
CVE-2026-49336
was published
for
@microsoft/kiota-http-fetchlibrary
(npm)
Jun 26, 2026
tuf has platform-dependent delegation path matching
Moderate
GHSA-qp9x-wp8f-qgjj
was published
for
tuf
(pip)
May 28, 2026
Envoy AI Proxy - MCP Message Smuggling Vulnerability
Moderate
GHSA-4gph-2hhr-5mwg
was published
for
github.com/envoyproxy/ai-gateway
(Go)
May 19, 2026
This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back...
Moderate
Unreviewed
CVE-2023-46218
was published
Dec 7, 2023
justhtml includes multiple security fixes
Moderate
GHSA-c9vm-hv86-f23r
was published
for
justhtml
(pip)
Apr 10, 2026
OpenClaw: Windows-compatible env override keys could bypass system.run approval binding
Moderate
GHSA-98ch-45wp-ch47
was published
for
openclaw
(npm)
Apr 7, 2026
Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client...
Moderate
Unreviewed
CVE-2026-3532
was published
Mar 26, 2026
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner,...
Moderate
Unreviewed
CVE-2004-1083
was published
Apr 29, 2022
OpenClaw: Exec approval allowlist patterns overmatched on POSIX paths
Moderate
GHSA-f8r2-vg7x-gh8m
was published
for
openclaw
(npm)
Mar 13, 2026
File Browser has an Authentication Bypass in User Password Update
Moderate
CVE-2026-25889
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Feb 10, 2026
elysia-cors Origin Validation Error
Moderate
CVE-2025-50864
was published
for
@elysiajs/cors
(npm)
Aug 20, 2025
Flask-CORS vulnerable to Improper Handling of Case Sensitivity
Moderate
CVE-2024-6866
was published
for
flask-cors
(pip)
Mar 20, 2025
Spring Framework DataBinder Case Sensitive Match Exception
Moderate
CVE-2024-38820
was published
for
org.springframework:spring-context
(Maven)
Oct 18, 2024
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating...
Moderate
Unreviewed
CVE-2021-25920
was published
May 24, 2022
Apache Camel: Camel Message Header Injection via Improper Filtering
Moderate
CVE-2025-27636
was published
for
org.apache.camel:camel-support
(Maven)
Mar 9, 2025
Drupal core Access bypass
Moderate
CVE-2024-55634
was published
for
drupal/core
(Composer)
Dec 10, 2024
Spring LDAP data exposure vulnerability
Moderate
CVE-2024-38829
was published
for
org.springframework.ldap:spring-ldap-core
(Maven)
Dec 4, 2024
social-auth-app-django affected by Improper Handling of Case Sensitivity
Moderate
CVE-2024-32879
was published
for
social-auth-app-django
(pip)
Apr 24, 2024
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source...
Moderate
Unreviewed
CVE-2003-0411
was published
Apr 29, 2022
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs...
Moderate
Unreviewed
CVE-2001-0795
was published
Apr 30, 2022
IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by...
Moderate
Unreviewed
CVE-2000-0497
was published
Apr 30, 2022
ProTip!
Advisories are also available from the
GraphQL API