GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
98 advisories
Filter by severity
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and...
High
Unreviewed
CVE-2026-70429
was published
Aug 5, 2026
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
High
CVE-2026-54763
was published
for
github.com/traefik/traefik/v2
(Go)
Aug 6, 2026
A flaw was found in Keycloak's Authorization Services. The component responsible for matching...
High
Unreviewed
CVE-2026-15573
was published
Aug 5, 2026
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
High
CVE-2026-71315
was published
for
nuxt
(npm)
Aug 5, 2026
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
High
CVE-2026-50559
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
Jul 29, 2026
Logto performs principal lookup without normalizing email and identifier strings, enabling...
Critical
Unreviewed
CVE-2026-15617
was published
Jul 23, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Moderate
GHSA-89vp-jrxv-24w8
was published
for
jupyterlab
(pip)
Jul 22, 2026
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive...
Moderate
Unreviewed
CVE-2026-3833
was published
Apr 30, 2026
OpenFGA Improper Policy Enforcement
Low
CVE-2026-55170
was published
for
github.com/openfga/openfga
(Go)
Jun 18, 2026
MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
Moderate
CVE-2026-57441
was published
for
@bitbonsai/mcpvault
(npm)
Jun 18, 2026
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
High
CVE-2026-45135
was published
for
github.com/caddyserver/caddy/v2
(Go)
May 18, 2026
Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)
High
CVE-2026-54567
was published
for
Flask-Reuploaded
(pip)
Jul 17, 2026
Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose...
High
Unreviewed
CVE-2026-62230
was published
Jul 17, 2026
SafeInstall agent guard shell parsing can miss raw package execution
High
GHSA-xrmc-c5cg-rv7x
was published
for
safeinstall-cli
(npm)
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
CVE-2026-48595
was published
for
tesla
(Erlang)
Jul 10, 2026
A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected...
Low
Unreviewed
CVE-2026-14617
was published
Jul 4, 2026
A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to...
Moderate
Unreviewed
CVE-2025-4035
was published
Apr 29, 2025
Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a...
Low
Unreviewed
CVE-2026-58057
was published
Jun 28, 2026
Authelia has an Edge Case Access Control Rule Mismatch
Low
CVE-2026-48794
was published
for
github.com/authelia/authelia/v4
(Go)
Jun 26, 2026
@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
Moderate
CVE-2026-49336
was published
for
@microsoft/kiota-http-fetchlibrary
(npm)
Jun 26, 2026
Authelia Missing Username Canonicalization in Basic Auth (LDAP)
Low
CVE-2026-47203
was published
for
github.com/authelia/authelia/v4
(Go)
May 29, 2026
jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
High
CVE-2026-54528
was published
for
jupyterlab-git
(pip)
Jun 19, 2026
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
Low
GHSA-8678-w3jw-xfc2
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
High
CVE-2026-53721
was published
for
nuxt
(npm)
Jun 16, 2026
TYPO3 CMS has Broken Access Control in its Form Framework
High
CVE-2026-47346
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
ProTip!
Advisories are also available from the
GraphQL API