GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
32 advisories
Filter by severity
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a...
High
Unreviewed
CVE-2026-105050
was published
Oct 3, 2026
PyJWT: Non-canonical signature segments enable raw-token revocation bypass
Moderate
CVE-2026-102269
was published
for
PyJWT
(pip)
Sep 29, 2026
stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing...
Moderate
Unreviewed
CVE-2026-100674
was published
Sep 26, 2026
OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026...
Moderate
Unreviewed
CVE-2026-100547
was published
Sep 26, 2026
Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used...
Moderate
Unreviewed
CVE-2026-100230
was published
Sep 25, 2026
django-allauth before 65.19.4 does not have the expected limits on failed login attempts because,...
Low
Unreviewed
CVE-2026-97764
was published
Sep 25, 2026
Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0...
Moderate
Unreviewed
CVE-2026-95811
was published
Sep 25, 2026
SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is...
Low
Unreviewed
CVE-2026-79300
was published
Sep 13, 2026
The cohttp package before 6.3.0 for OCaml allows directory traversal.
High
Unreviewed
CVE-2026-82481
was published
Aug 29, 2026
Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer
in...
Moderate
Unreviewed
CVE-2026-76203
was published
Aug 19, 2026
Guzzle: Noncanonical host can bypass host-based checks
High
CVE-2026-69246
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
Guzzle: Noncanonical cookie domain keeps subdomain scope
Moderate
CVE-2026-69245
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
Moderate
CVE-2026-7120
was published
for
@fastify/static
(npm)
Jul 24, 2026
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are...
Critical
Unreviewed
CVE-2026-15704
was published
Jul 24, 2026
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Critical
CVE-2026-73420
was published
for
@auth/core
(npm)
Jul 23, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Moderate
CVE-2026-73416
was published
for
jupyterlab
(pip)
Jul 22, 2026
Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass
Critical
CVE-2026-44180
was published
for
jupyter_enterprise_gateway
(pip)
Jun 3, 2026
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
High
CVE-2026-42462
was published
for
@fedify/fedify
(npm)
May 26, 2026
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
High
CVE-2026-45022
was published
for
github.com/go-git/go-git/v5
(Go)
May 11, 2026
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
Moderate
CVE-2026-39409
was published
for
hono
(npm)
Apr 8, 2026
Vite: `server.fs.deny` bypassed with queries
High
CVE-2026-39364
was published
for
vite
(npm)
Apr 6, 2026
Rack:: Static header_rules bypass via URL-encoded paths
Moderate
CVE-2026-34786
was published
for
rack
(RubyGems)
Apr 2, 2026
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url...
Moderate
Unreviewed
CVE-2026-34475
was published
Mar 27, 2026
OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths
Moderate
CVE-2026-32033
was published
for
openclaw
(npm)
Mar 3, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP
High
CVE-2026-24895
was published
for
github.com/dunglas/frankenphp
(Go)
Feb 12, 2026
ProTip!
Advisories are also available from the
GraphQL API