GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,169
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
385 advisories
Filter by severity
OpenAM has Unsafe Java Deserialization via SNS
High
CVE-2026-45794
was published
for
org.openidentityplatform.openam:openam-push-notification
(Maven)
Jun 25, 2026
OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage
Critical
CVE-2026-45051
was published
for
org.openidentityplatform.openam:openam-auth-webauthn
(Maven)
Jun 24, 2026
jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
High
CVE-2026-54512
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI
Critical
CVE-2026-46495
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jun 22, 2026
Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types
High
CVE-2026-44795
was published
for
io.spinnaker.orca:orca-core
(Maven)
Jun 22, 2026
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
High
CVE-2025-27511
was published
for
org.geoserver.extension:gs-db2
(Maven)
Jun 11, 2026
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
High
CVE-2026-41731
was published
for
org.springframework.kafka:spring-kafka
(Maven)
Jun 10, 2026
Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41635 Incomplete Fix)
Critical
CVE-2026-42779
was published
for
org.apache.mina:mina-core
(Maven)
May 1, 2026
Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)
Critical
CVE-2026-42778
was published
for
org.apache.mina:mina-core
(Maven)
May 1, 2026
fabric-sdk-java has ObjectInputStream.readObject() without ObjectInputFilter, which allows Java deserialization RCE
Critical
CVE-2026-41586
was published
for
org.hyperledger.fabric-sdk-java:fabric-sdk-java
(Maven)
Apr 29, 2026
Jenkins Matrix Authorization Strategy Plugin: Unsafe deserialization allows invocation of parameterless constructors
Moderate
CVE-2026-42521
was published
for
org.jenkins-ci.plugins:matrix-auth
(Maven)
Apr 29, 2026
Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)
Critical
CVE-2026-41409
was published
for
org.apache.mina:mina-core
(Maven)
Apr 27, 2026
Apache Camel's Camel-Mail component is vulnerable to Camel message header injection
Critical
CVE-2026-33454
was published
for
org.apache.camel:camel-mail
(Maven)
Apr 27, 2026
Apache Camel-Consul component vulnerable to Deserialization of Untrusted Data
Moderate
CVE-2026-27172
was published
for
org.apache.camel:camel-consul
(Maven)
Apr 27, 2026
Apache Camel-Infinispan Component Vulnerable to Deserialization of Untrusted Data
High
CVE-2026-40858
was published
for
org.apache.camel:camel-infinispan
(Maven)
Apr 27, 2026
Apache MINA vulnerable to Deserialization of Untrusted Data
Critical
CVE-2026-41635
was published
for
org.apache.mina:mina-core
(Maven)
Apr 27, 2026
Camel-MINA Vulnerable to Deserialization of Untrusted Data
High
CVE-2026-40473
was published
for
org.apache.camel:camel-mina
(Maven)
Apr 27, 2026
Camel-PQC Vulnerable to Deserialization of Untrusted Data
High
CVE-2026-40048
was published
for
org.apache.camel:camel-pqc
(Maven)
Apr 27, 2026
Apache DolphinScheduler RPC module has a Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-62233
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Apr 24, 2026
camel-infinispan Vulnerable to Deserialization of Untrusted Data
High
CVE-2026-6857
was published
for
org.apache.camel:camel-infinispan
(Maven)
Apr 22, 2026
Apache Storm: Deserialization of Untrusted Data vulnerability
High
CVE-2026-35337
was published
for
org.apache.storm:storm-client
(Maven)
Apr 13, 2026
OpenIdentityPlatform OpenAM: Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM
Critical
CVE-2026-33439
was published
for
org.openidentityplatform.openam:openam
(Maven)
Apr 7, 2026
splunk-otel-javaagent: Unsafe deserialization in RMI instrumentation may lead to Remote Code Execution
Critical
GHSA-h8w2-rv57-vc6f
was published
for
com.splunk:splunk-otel-javaagent
(Maven)
Mar 26, 2026
dd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code execution
Critical
CVE-2026-33728
was published
for
com.datadoghq:dd-java-agent
(Maven)
Mar 26, 2026
OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution
Critical
CVE-2026-33701
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Mar 25, 2026
ProTip!
Advisories are also available from the
GraphQL API