GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
162 advisories
Filter by severity
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
High
GHSA-9c5c-9qcx-q35q
was published
for
@nestjs/platform-fastify
(npm)
Sep 30, 2026
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
Moderate
CVE-2026-86818
was published
for
fast-uri
(npm)
Sep 29, 2026
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
Moderate
GHSA-g57g-f23g-4646
was published
for
nodemailer
(npm)
Sep 29, 2026
adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
Moderate
GHSA-p634-w6r4-rjp2
was published
for
adm-zip
(npm)
Sep 29, 2026
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
High
CVE-2026-84394
was published
for
fast-uri
(npm)
Sep 28, 2026
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
High
CVE-2026-56669
was published
for
elysia
(npm)
Sep 23, 2026
http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches(...
High
Unreviewed
CVE-2026-93750
was published
Sep 18, 2026
Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib...
High
Unreviewed
CVE-2026-92597
was published
Sep 17, 2026
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain...
High
Unreviewed
CVE-2026-92598
was published
Sep 17, 2026
A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the...
Low
Unreviewed
CVE-2026-91835
was published
Sep 15, 2026
Traefik entrypoint header-name sanitization bypassed via request trailers
High
CVE-2026-88004
was published
for
github.com/traefik/traefik/v3
(Go)
Sep 10, 2026
Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed...
Moderate
Unreviewed
CVE-2026-87627
was published
Sep 9, 2026
Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to...
High
Unreviewed
CVE-2026-82537
was published
Sep 8, 2026
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
Moderate
GHSA-wmmp-3585-3rmp
was published
for
nodemailer
(npm)
Sep 8, 2026
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
Moderate
GHSA-cc9r-2j5m-2m83
was published
for
nodemailer
(npm)
Sep 8, 2026
Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a...
High
Unreviewed
CVE-2026-81378
was published
Sep 8, 2026
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
Moderate
CVE-2026-73846
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 3, 2026
Mail: Email address spoofing via malformed RFC 2047 encoded-words
Moderate
CVE-2026-63435
was published
for
mail
(RubyGems)
Sep 2, 2026
fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
High
CVE-2026-75931
was published
for
fast-uri
(npm)
Sep 2, 2026
The "stringprep" module didn't process characters from RFC 3454 tables
B.2 or B.3 correctly: the...
Moderate
Unreviewed
CVE-2026-17084
was published
Aug 18, 2026
Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before...
High
Unreviewed
CVE-2026-73614
was published
Aug 13, 2026
Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where...
High
Unreviewed
CVE-2026-73615
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
Low
Unreviewed
CVE-2026-18246
was published
Aug 12, 2026
Apache Airflow Backfill API parser discrepancy permits cross-DAG authorization bypass
High
CVE-2026-68968
was published
for
apache-airflow
(pip)
Aug 12, 2026
ProTip!
Advisories are also available from the
GraphQL API