GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,169
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
26 advisories
Filter by severity
ECS zero scoped answers are stored in the packet cache while they should not. This impacts only...
Moderate
Unreviewed
CVE-2026-40012
was published
Jun 25, 2026
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
Moderate
CVE-2026-9678
was published
for
undici
(npm)
Jun 18, 2026
@angular/service-worker: Request Credential & Cache Policy Stripping
Moderate
CVE-2026-50184
was published
for
@angular/service-worker
(npm)
Jun 15, 2026
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
Moderate
CVE-2026-50169
was published
for
@angular/service-worker
(npm)
Jun 15, 2026
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when...
Moderate
Unreviewed
CVE-2026-41841
was published
Jun 9, 2026
Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage
Moderate
CVE-2026-44457
was published
for
hono
(npm)
May 9, 2026
Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters
Moderate
CVE-2026-30246
was published
for
github.com/gofiber/fiber/v3
(Go)
Apr 28, 2026
IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching...
Moderate
Unreviewed
CVE-2025-14806
was published
Mar 18, 2026
Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception
Moderate
CVE-2026-24472
was published
for
hono
(npm)
Jan 27, 2026
axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header
Moderate
CVE-2025-69202
was published
for
axios-cache-interceptor
(npm)
Dec 30, 2025
Android App "Brother iPrint&Scan" versions 6.13.7 and earlier improperly uses an external cache...
Moderate
Unreviewed
CVE-2025-64696
was published
Dec 9, 2025
The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1,...
Moderate
Unreviewed
CVE-2025-43392
was published
Nov 4, 2025
A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored...
Moderate
Unreviewed
CVE-2025-9901
was published
Sep 3, 2025
Next.js Affected by Cache Key Confusion for Image Optimization API Routes
Moderate
CVE-2025-57752
was published
for
next
(npm)
Aug 29, 2025
A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on...
Moderate
Unreviewed
CVE-2025-5141
was published
Jun 17, 2025
An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access...
Moderate
Unreviewed
CVE-2025-4233
was published
Jun 13, 2025
JetBrains Ktor information disclosure
Moderate
CVE-2024-49580
was published
for
io.ktor:ktor-client-core-jvm
(Maven)
Oct 17, 2024
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions ...
Moderate
Unreviewed
CVE-2024-41906
was published
Aug 13, 2024
SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic...
Moderate
Unreviewed
CVE-2024-33004
was published
May 14, 2024
CoreDNS may return invalid cache entries
Moderate
CVE-2024-0874
was published
for
github.com/coredns/coredns
(Go)
Apr 25, 2024
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client....
Moderate
Unreviewed
CVE-2023-45696
was published
Feb 10, 2024
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37...
Moderate
Unreviewed
CVE-2021-44854
was published
Dec 26, 2022
Batched HTTP requests may set incorrect `cache-control` response header
Moderate
GHSA-8r69-3cvp-wxc3
was published
for
@apollo/server
(npm)
Nov 2, 2022
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16. An app...
Moderate
Unreviewed
CVE-2022-32909
was published
Nov 2, 2022
rdiffweb vulnerable to Use of Cache Containing Sensitive Information
Moderate
CVE-2022-3292
was published
for
rdiffweb
(pip)
Sep 29, 2022
ProTip!
Advisories are also available from the
GraphQL API