GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
58 advisories
Filter by severity
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on...
Critical
Unreviewed
CVE-2026-15587
was published
Aug 5, 2026
Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-16381
was published
Jul 21, 2026
Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox...
Critical
Unreviewed
CVE-2026-16375
was published
Jul 21, 2026
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-16358
was published
Jul 21, 2026
Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-16349
was published
Jul 21, 2026
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
Critical
GHSA-g53w-w6mj-hrpp
was published
for
github.com/Kuadrant/mcp-gateway
(Go)
May 19, 2026
An unauthenticated remote attacker can execute any command on the affected device due to not...
Critical
Unreviewed
CVE-2023-49899
was published
Jul 16, 2026
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
Critical
CVE-2026-54069
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
Insufficient policy enforcement in Speech in Google Chrome prior to 150.0.7871.47 allowed a...
Critical
Unreviewed
CVE-2026-14105
was published
Jul 1, 2026
Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
Critical
CVE-2026-55791
was published
for
craftcms/cms
(Composer)
Jun 19, 2026
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-12304
was published
Jun 16, 2026
The Model Context Protocol has a security warning advising servers to validate the "Origin"...
Critical
Unreviewed
CVE-2026-11624
was published
Jun 13, 2026
Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload
Critical
CVE-2026-48063
was published
for
@whiskeysockets/baileys
(npm)
Jun 10, 2026
SillyTavern has Authentication Bypass via SSO Header Injection
Critical
CVE-2026-44649
was published
for
sillytavern
(npm)
May 12, 2026
MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution
Critical
CVE-2026-2611
was published
for
mlflow
(pip)
May 19, 2026
Langflow CORS misconfiguration enables Account Takeover and RCE
Critical
CVE-2025-34291
was published
for
langflow
(pip)
Dec 6, 2025
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2026-42901
was published
May 26, 2026
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-8950
was published
May 19, 2026
Unity Catalog has a JWT Issuer Validation Bypass tht Allows Complete User Impersonation
Critical
CVE-2026-27478
was published
for
io.unitycatalog:unitycatalog-server
(Maven)
May 11, 2026
Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute...
Critical
Unreviewed
CVE-2026-6508
was published
May 7, 2026
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
Critical
CVE-2024-25124
was published
for
github.com/gofiber/fiber/v2
(Go)
Feb 22, 2024
Same-origin policy bypass in the Networking: JAR component. This vulnerability affects Firefox <...
Critical
Unreviewed
CVE-2026-2790
was published
Feb 24, 2026
Apache Camel: KeycloakSecurityPolicy does not validate issuer of JWT tokens against configured realm
Critical
CVE-2026-23552
was published
for
org.apache.camel:camel-keycloak
(Maven)
Feb 23, 2026
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in...
Critical
Unreviewed
CVE-2025-63386
was published
Dec 18, 2025
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in...
Critical
Unreviewed
CVE-2025-63388
was published
Dec 18, 2025
ProTip!
Advisories are also available from the
GraphQL API