GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,002
Maven
5,000+
npm
4,724
NuGet
788
pip
4,335
Pub
12
RubyGems
987
Rust
1,136
Swift
50
Unreviewed advisories
All unreviewed
5,000+
126 advisories
Filter by severity
Vert.x Web static handler component cache can be manipulated to deny the access to static files
Moderate
CVE-2026-1002
was published
for
io.vertx:vertx-core
(Maven)
Jan 15, 2026
h3 v1 has Request Smuggling (TE.TE) issue
High
CVE-2026-23527
was published
for
h3
(npm)
Jan 15, 2026
AIOHTTP has unicode match groups in regexes for ASCII protocol elements
Low
CVE-2025-69225
was published
for
aiohttp
(pip)
Jan 5, 2026
AIOHTTP's unicode processing of header values could cause parsing discrepancies
Low
CVE-2025-69224
was published
for
aiohttp
(pip)
Jan 5, 2026
flagd: Multiple Go Runtime CVEs Impact Security and Availability
High
GHSA-4c5f-9mj4-m247
was published
for
github.com/open-feature/flagd/core
(Go)
Jan 5, 2026
Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
Moderate
GHSA-q7jf-gf43-6x6p
was published
for
hono
(npm)
Oct 24, 2025
Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability
Critical
CVE-2025-55315
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Oct 14, 2025
Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
Moderate
CVE-2025-59822
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 23, 2025
Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions
Low
CVE-2025-58056
was published
for
io.netty:netty-codec-http
(Maven)
Sep 4, 2025
Eventlet affected by HTTP request smuggling in unparsed trailers
Moderate
CVE-2025-58068
was published
for
eventlet
(pip)
Aug 29, 2025
mitmproxy binaries embed a vulnerable python-hyper/h2 dependency
Moderate
GHSA-63cx-g855-hvv4
was published
for
mitmproxy
(pip)
Aug 25, 2025
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
Low
CVE-2025-53643
was published
for
aiohttp
(pip)
Jul 14, 2025
Next.JS vulnerability can lead to DoS via cache poisoning
High
CVE-2025-49826
was published
for
next
(npm)
Jul 3, 2025
Next.js has a Cache poisoning vulnerability due to omission of the Vary header
Low
CVE-2025-49005
was published
for
next
(npm)
Jul 3, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
Moderate
CVE-2025-6442
was published
for
webrick
(RubyGems)
Jun 26, 2025
Pingora has a Request Smuggling Vulnerability
High
CVE-2025-4366
was published
for
pingora-core
(Rust)
Jun 20, 2025
Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies
High
CVE-2025-41235
was published
for
org.springframework.cloud:spring-cloud-gateway-server
(Maven)
May 30, 2025
Duplicate Advisory: Pingora Request Smuggling and Cache Poisoning
High
GHSA-3qmp-g57h-rxf2
was published
for
pingora-core
(Rust)
May 22, 2025
•
withdrawn
h11 accepts some malformed Chunked-Encoding bodies
Critical
CVE-2025-43859
was published
for
h11
(pip)
Apr 24, 2025
croogo Host header injection
Moderate
CVE-2024-29643
was published
for
croogo/croogo
(Composer)
Apr 21, 2025
CVE-2025-1386- Query smuggling in ch-go library
Moderate
CVE-2025-1386
was published
for
github.com/ClickHouse/ch-go
(Go)
Apr 12, 2025
RoadRunner is at risk of HTTP Request/Response Smuggling through vulnerable dependency
Critical
CVE-2025-22871
was published
for
spiral/roadrunner
(Composer)
Apr 8, 2025
Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers
High
CVE-2025-31137
was published
for
@react-router/express
(npm)
Apr 1, 2025
Gunicorn HTTP Request/Response Smuggling vulnerability
High
CVE-2024-6827
was published
for
gunicorn
(pip)
Mar 20, 2025
io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
High
CVE-2024-12397
was published
for
io.quarkus.http:quarkus-http-core
(Maven)
Dec 12, 2024
ProTip!
Advisories are also available from the
GraphQL API