GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
146 advisories
Filter by severity
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
High
GHSA-ghvf-qf6h-g8x5
was published
for
@nocobase/server
(npm)
Aug 20, 2026
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
Moderate
GHSA-hjwh-xvfw-qrwj
was published
for
mcp-searxng
(npm)
Aug 19, 2026
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
Moderate
GHSA-92hr-gmr6-h8cp
was published
for
ep_etherpad-lite
(npm)
Aug 17, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors
Moderate
CVE-2026-55102
was published
for
hashi-vault-js
(npm)
Aug 13, 2026
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
Low
GHSA-gwfq-86j8-7qhv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
High
CVE-2026-69247
was published
for
cryptography
(pip)
Aug 3, 2026
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
High
CVE-2026-73409
was published
for
@budibase/server
(npm)
Jul 24, 2026
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
Moderate
CVE-2026-59943
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath
Moderate
CVE-2026-54561
was published
for
mcp-memory-keeper
(npm)
Jul 17, 2026
@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state
Moderate
GHSA-qcr8-x557-7cp3
was published
for
@asymmetric-effort/specifyjs
(npm)
Jul 2, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
Moderate
GHSA-6g9v-7gq3-p2c6
was published
for
surrealdb
(Rust)
Jul 1, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
High
GHSA-cc8f-fcx3-gpjr
was published
for
surrealdb
(Rust)
Jun 19, 2026
canto-saas-api: OAuth credentials exposed in URL query string and exception messages
Moderate
CVE-2026-55375
was published
for
jleehr/canto-saas-api
(Composer)
Jun 19, 2026
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
Critical
CVE-2026-48039
was published
for
meta-ads-mcp
(pip)
Jun 11, 2026
Spring Web Services: SOAP security faults leak Spring Security account state
Moderate
CVE-2026-40997
was published
for
org.springframework.ws:spring-ws-security
(Maven)
Jun 11, 2026
Spring Data REST potentially exposes persistence-layer internals to HTTP clients
Moderate
CVE-2026-41730
was published
for
org.springframework.data:spring-data-rest-core
(Maven)
Jun 10, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic
Low
CVE-2026-45723
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers
Moderate
CVE-2026-47248
was published
for
parse-server
(npm)
May 29, 2026
Keycloak Generates an Error Message Containing Sensitive Information
Moderate
CVE-2026-9794
was published
for
org.keycloak:keycloak-services
(Maven)
May 28, 2026
Algernon: Single-file mode unconditionally enables debug mode
High
CVE-2026-45728
was published
for
github.com/xyproto/algernon
(Go)
May 19, 2026
Vaadin Build Plugins is Affected by a Possible Information Disclosure Vulnerability
Low
CVE-2026-7860
was published
for
com.vaadin:flow-gradle-plugin
(Maven)
May 19, 2026
vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak
Moderate
CVE-2026-44002
was published
for
vm2
(npm)
May 7, 2026
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information
High
CVE-2026-42459
was published
for
github.com/free5gc/udm
(Go)
May 7, 2026
Flight vulnerable to sensitive information disclosure via default error handler
High
CVE-2026-42552
was published
for
flightphp/core
(Composer)
May 6, 2026
PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI
Moderate
CVE-2026-44226
was published
for
pyload-ng
(pip)
May 6, 2026
ProTip!
Advisories are also available from the
GraphQL API