GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,562
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,807
Pub
13
RubyGems
1,038
Rust
1,238
Swift
53
Unreviewed advisories
All unreviewed
5,000+
39 advisories
Filter by severity
An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2026-4296
was published
Apr 22, 2026
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
Moderate
CVE-2026-25542
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Istio: AuthorizationPolicy serviceAccounts regex injection via unescaped dots
Moderate
CVE-2026-39350
was published
for
istio.io/istio
(Go)
Apr 16, 2026
OpenClaw safeBins jq `$ENV` filter bypass allows environment variable disclosure
High
GHSA-jccr-rrw2-vc8h
was published
for
openclaw
(npm)
Mar 31, 2026
SVG Dimension Capping Bypass via XML Comment Injection in @dicebear/converter ensureSize()
High
CVE-2026-33418
was published
for
@dicebear/converter
(npm)
Mar 20, 2026
league/commonmark has an embed extension allowed_domains bypass
Moderate
CVE-2026-33347
was published
for
league/commonmark
(Composer)
Mar 19, 2026
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
Moderate
CVE-2026-3419
was published
for
fastify
(npm)
Mar 5, 2026
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
Critical
CVE-2026-25896
was published
for
fast-xml-parser
(npm)
Feb 20, 2026
Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns
Moderate
CVE-2026-25479
was published
for
litestar
(pip)
Feb 9, 2026
Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing
Moderate
CVE-2026-24398
was published
for
hono
(npm)
Jan 27, 2026
FastAPI Guard has a regex bypass
High
CVE-2025-54365
was published
for
fastapi-guard
(pip)
Jul 23, 2025
A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow...
High
Unreviewed
CVE-2025-20139
was published
Apr 2, 2025
It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript,...
Moderate
Unreviewed
CVE-2025-1934
was published
Mar 4, 2025
parse-uri Regular expression Denial of Service (ReDoS)
Moderate
CVE-2024-36751
was published
for
parse-uri
(npm)
Jan 16, 2025
Butterfly's parseJSON, getJSON functions eval malicious input, leading to remote code execution (RCE)
Moderate
GHSA-mpcw-3j5p-p99x
was published
for
org.openrefine.dependencies:butterfly
(Maven)
Oct 24, 2024
The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security...
Moderate
Unreviewed
CVE-2024-6641
was published
Sep 18, 2024
An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an...
High
Unreviewed
CVE-2024-2223
was published
Apr 9, 2024
A user authorized to perform database queries may trigger denial of service by issuing specially...
Moderate
Unreviewed
CVE-2020-7929
was published
May 24, 2022
Incorrect default pattern in Jenkins Audit Trail Plugin
Moderate
CVE-2020-2288
was published
for
org.jenkins-ci.plugins:audit-trail
(Maven)
May 24, 2022
A vulnerability in the Split DNS feature of Cisco IOS Software and Cisco IOS XE Software could...
High
Unreviewed
CVE-2020-3408
was published
May 24, 2022
A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive...
Moderate
Unreviewed
CVE-2020-1741
was published
May 24, 2022
An issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c does not restrict regular...
Critical
Unreviewed
CVE-2019-12798
was published
May 24, 2022
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST...
Moderate
Unreviewed
CVE-2019-11391
was published
May 24, 2022
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST...
Moderate
Unreviewed
CVE-2019-11389
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API