GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,169
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
177 advisories
Filter by severity
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
High
CVE-2026-55487
was published
for
pnpm
(npm)
Jun 26, 2026
chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution
High
GHSA-9g5q-2w5x-hmxf
was published
for
github.com/go-chi/chi/middleware
(Go)
Jun 25, 2026
Anki's local HTTP server does not sufficiently validate requests
High
GHSA-869j-r97x-hx2g
was published
for
aqt
(pip)
Jun 19, 2026
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
High
GHSA-f4xh-w4cj-qxq8
was published
for
langsmith
(pip)
Jun 19, 2026
Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests
High
GHSA-v3f4-w7r7-v3hm
was published
for
@zenalexa/unicli
(npm)
Jun 19, 2026
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
High
CVE-2026-55660
was published
for
@tinacms/app
(npm)
Jun 19, 2026
Blocky DNSSEC validation bypass and validation-cache scope pollution
High
GHSA-x845-2f78-7v36
was published
for
github.com/0xERR0R/blocky
(Go)
Jun 19, 2026
Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)
High
GHSA-v52w-28xh-v562
was published
for
@kozou/api
(npm)
Jun 19, 2026
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
High
CVE-2026-6734
was published
for
undici
(npm)
Jun 19, 2026
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
High
GHSA-vmf9-xx9w-86wx
was published
for
praisonai
(pip)
Jun 18, 2026
Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
High
CVE-2026-54007
was published
for
open-webui
(pip)
Jun 17, 2026
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted...
High
Unreviewed
CVE-2026-47825
was published
Jun 15, 2026
@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass
High
CVE-2026-50168
was published
for
@angular/platform-server
(npm)
Jun 15, 2026
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
High
GHSA-j9gf-vw2f-9hrw
was published
for
com.appsmith:server
(Maven)
Jun 12, 2026
Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1...
High
Unreviewed
CVE-2026-45173
was published
Jun 12, 2026
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross...
High
Unreviewed
CVE-2026-41700
was published
Jun 11, 2026
NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub)...
High
Unreviewed
CVE-2026-10846
was published
Jun 10, 2026
Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote...
High
Unreviewed
CVE-2026-11693
was published
Jun 9, 2026
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
High
CVE-2026-46701
was published
for
network-ai
(npm)
May 21, 2026
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service...
High
Unreviewed
CVE-2025-71214
was published
May 21, 2026
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection...
High
Unreviewed
CVE-2025-71217
was published
May 21, 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
High
Unreviewed
CVE-2026-34927
was published
May 21, 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
High
Unreviewed
CVE-2026-34929
was published
May 21, 2026
An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to...
High
Unreviewed
CVE-2025-71213
was published
May 21, 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
High
Unreviewed
CVE-2026-45206
was published
May 21, 2026
ProTip!
Advisories are also available from the
GraphQL API