GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,095 advisories
Filter by severity
When an Event Publisher output adapter is configured with irrelevant properties, the affected...
Moderate
Unreviewed
CVE-2026-0637
was published
Aug 6, 2026
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local...
Moderate
Unreviewed
CVE-2026-20289
was published
Aug 5, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores...
High
Unreviewed
CVE-2026-12947
was published
Jul 30, 2026
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a...
Moderate
Unreviewed
CVE-2026-44105
was published
Jul 30, 2026
The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy...
Low
Unreviewed
CVE-2026-59326
was published
Jul 30, 2026
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Moderate
CVE-2026-54704
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain...
High
Unreviewed
CVE-2026-14528
was published
Jul 28, 2026
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0...
Moderate
Unreviewed
CVE-2026-1918
was published
Jul 28, 2026
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
Low
GHSA-2625-rw7m-5q5x
was published
for
hubuum_client
(Rust)
Jul 24, 2026
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
Low
Unreviewed
CVE-2026-64800
was published
Jul 23, 2026
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Moderate
CVE-2026-65589
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Moderate
GHSA-fmvg-vhqq-r2mj
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
Moderate
CVE-2026-59947
was published
for
composer/composer
(Composer)
Jul 20, 2026
OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the...
Moderate
Unreviewed
CVE-2026-62211
was published
Jul 17, 2026
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2...
High
Unreviewed
CVE-2026-40633
was published
Jul 15, 2026
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker...
Moderate
Unreviewed
CVE-2026-50316
was published
Jul 14, 2026
Various sensitive information such as passwords and charging card UIDs are written to log files.
Critical
Unreviewed
CVE-2026-22098
was published
Jul 13, 2026
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The...
Moderate
Unreviewed
CVE-2026-56459
was published
Jul 9, 2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0...
Moderate
Unreviewed
CVE-2026-46467
was published
Jul 3, 2026
A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0...
Moderate
Unreviewed
CVE-2026-8482
was published
Jul 2, 2026
Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information...
Moderate
Unreviewed
CVE-2026-49088
was published
Jul 1, 2026
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM...
Moderate
Unreviewed
CVE-2026-12086
was published
Jun 30, 2026
Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed...
Moderate
Unreviewed
CVE-2026-13750
was published
Jun 29, 2026
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information...
Moderate
Unreviewed
CVE-2026-56457
was published
Jun 29, 2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure...
Moderate
Unreviewed
CVE-2025-59868
was published
Jun 27, 2026
ProTip!
Advisories are also available from the
GraphQL API