GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
643 advisories
Filter by severity
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Moderate
CVE-2026-73419
was published
for
@auth/core
(npm)
Jul 23, 2026
Netty has Insufficient Bailiwick Validation for NS Records
High
CVE-2026-47691
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
High
CVE-2026-45674
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
High
CVE-2026-54007
was published
for
open-webui
(pip)
Jun 17, 2026
The web
interface of the affected
device relies on the HTTP referrer header as part of
request...
Moderate
Unreviewed
CVE-2026-15141
was published
Aug 13, 2026
The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys...
Moderate
Unreviewed
CVE-2026-18676
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials...
High
Unreviewed
CVE-2026-18847
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive...
High
Unreviewed
CVE-2026-18098
was published
Aug 12, 2026
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due...
High
Unreviewed
CVE-2026-16745
was published
Jul 23, 2026
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized...
High
Unreviewed
CVE-2026-56179
was published
Aug 11, 2026
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became...
High
Unreviewed
CVE-2026-19418
was published
Aug 11, 2026
Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability...
High
Unreviewed
CVE-2026-66732
was published
Aug 6, 2026
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
Moderate
CVE-2026-55767
was published
for
guzzlehttp/guzzle
(Composer)
Jun 19, 2026
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity...
High
Unreviewed
CVE-2026-16442
was published
Aug 5, 2026
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on...
Critical
Unreviewed
CVE-2026-15587
was published
Aug 5, 2026
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
Moderate
CVE-2026-70599
was published
for
electron
(npm)
Aug 5, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-66317
was published
Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-66318
was published
Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-66316
was published
Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-66322
was published
Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-66313
was published
Aug 4, 2026
Guzzle: Noncanonical cookie domain keeps subdomain scope
Moderate
CVE-2026-69245
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote...
Moderate
Unreviewed
CVE-2026-17754
was published
Jul 30, 2026
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote...
Moderate
Unreviewed
CVE-2026-17787
was published
Jul 30, 2026
Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a...
Moderate
Unreviewed
CVE-2026-17748
was published
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API