GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
100 advisories
Filter by severity
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
Moderate
CVE-2026-63405
was published
for
github.com/anycable/anycable
(Go)
Sep 18, 2026
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
Moderate
CVE-2026-73846
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 3, 2026
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
Moderate
CVE-2026-73840
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-248h-974q-xrc2
was published
for
com.getaxonflow:axonflow-sdk
(Maven)
May 6, 2026
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
Moderate
CVE-2026-55663
was published
for
mediasoup
(npm)
Aug 25, 2026
Triton VM Soundness Vulnerability due to Missing Constraint
Moderate
GHSA-vjf8-9fx6-mv6x
was published
for
triton-vm
(Rust)
Aug 18, 2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Moderate
CVE-2026-73419
was published
for
@auth/core
(npm)
Jul 23, 2026
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
Moderate
CVE-2026-54764
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
sigstore-go has a multi-log threshold bypass via single compromised log
Moderate
CVE-2026-49834
was published
for
github.com/sigstore/sigstore-go
(Go)
Jul 9, 2026
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
Moderate
CVE-2026-54288
was published
for
hono
(npm)
Jun 16, 2026
containerd: CRI checkpoint import allows local image tag poisoning
Moderate
CVE-2026-50195
was published
for
github.com/containerd/containerd/v2
(Go)
Jun 19, 2026
Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
Moderate
CVE-2026-59930
was published
for
mistune
(pip)
Jul 20, 2026
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
Moderate
CVE-2026-45792
was published
for
rtk
(Rust)
May 20, 2026
vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
Moderate
CVE-2026-47155
was published
for
vllm
(pip)
Jun 10, 2026
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
Moderate
CVE-2026-55430
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Zebra has sync restart poisoning from single unauthenticated peer via above-lookahead block
Moderate
CVE-2026-52737
was published
for
zebra-consensus
(Rust)
Jul 2, 2026
sigstore-js has Insufficient Verification of Data Authenticity
Moderate
CVE-2026-48816
was published
for
@sigstore/verify
(npm)
Jul 1, 2026
pnpm: Unsafe default behavior breaks integrity check
Moderate
CVE-2026-50573
was published
for
pnpm
(npm)
Jun 26, 2026
chi Has an IP Spoofing Vulnerability in `middleware.RealIP`
Moderate
GHSA-3fxj-6jh8-hvhx
was published
for
github.com/go-chi/chi/v5/middleware
(Go)
Jun 25, 2026
AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data
Moderate
CVE-2026-33731
was published
for
wwbn/avideo
(Composer)
Jun 22, 2026
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
Moderate
CVE-2026-48096
was published
for
github.com/openfga/openfga
(Go)
Jun 11, 2026
nimiq-primitives: BlockInclusionProof interlink issue when hops are empty
Moderate
CVE-2026-46539
was published
for
nimiq-primitives
(Rust)
May 21, 2026
arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLS
Moderate
GHSA-rc6v-5rmx-w5mv
was published
for
github.com/arnika-project/arnika
(Go)
May 15, 2026
nuts-node has JWT type confusion in v1 access token introspection that allows VP replay as access token
Moderate
CVE-2026-41164
was published
for
github.com/nuts-foundation/nuts-node
(Go)
May 5, 2026
Ollama vulnerable to Cross-Domain Token Exposure
Moderate
CVE-2025-51471
was published
for
github.com/ollama/ollama
(Go)
Jul 22, 2025
ProTip!
Advisories are also available from the
GraphQL API