GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
266 advisories
Filter by severity
Armatura One's backup and restore routine records the full database connection command, including...
High
Unreviewed
CVE-2026-94593
was published
Oct 3, 2026
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to...
High
Unreviewed
CVE-2025-71425
was published
Sep 27, 2026
Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before...
High
Unreviewed
CVE-2025-71423
was published
Sep 27, 2026
Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files...
High
Unreviewed
CVE-2026-82371
was published
Sep 24, 2026
Improper handling of sensitive data during IPsec policy creation and modification in Brocade...
High
Unreviewed
CVE-2026-82372
was published
Sep 24, 2026
Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before...
High
Unreviewed
CVE-2026-14443
was published
Sep 24, 2026
OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys...
High
Unreviewed
CVE-2026-95815
was published
Sep 22, 2026
Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of...
High
Unreviewed
CVE-2026-49810
was published
Sep 21, 2026
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
High
CVE-2026-86049
was published
for
jupyter_server
(pip)
Sep 17, 2026
admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing...
High
Unreviewed
CVE-2026-92918
was published
Sep 17, 2026
n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the...
High
Unreviewed
CVE-2026-85171
was published
Sep 3, 2026
Insertion of sensitive information into log file vulnerability in Apache Syncope.
When AES key...
High
Unreviewed
CVE-2026-87779
was published
Sep 14, 2026
The consul-template library is vulnerable to an information disclosure issue in its error...
High
Unreviewed
CVE-2026-87993
was published
Sep 10, 2026
Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE...
High
Unreviewed
CVE-2026-88883
was published
Sep 10, 2026
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an...
High
Unreviewed
CVE-2026-78627
was published
Sep 8, 2026
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file...
High
Unreviewed
CVE-2026-85174
was published
Sep 3, 2026
In affected versions of Octopus Server under certain circumstances it is possible for sensitive...
High
Unreviewed
CVE-2026-14163
was published
Aug 20, 2026
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the...
High
Unreviewed
CVE-2026-81705
was published
Aug 27, 2026
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver...
High
Unreviewed
CVE-2026-81715
was published
Aug 27, 2026
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
High
CVE-2026-61798
was published
for
io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl
(Maven)
Aug 20, 2026
A low privileged remote attacker can hijack an active administrative session without needing to...
High
Unreviewed
CVE-2026-14948
was published
Aug 20, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request...
High
Unreviewed
CVE-2019-25766
was published
Aug 19, 2026
Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's...
High
Unreviewed
CVE-2020-37267
was published
Aug 19, 2026
openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the ...
High
Unreviewed
CVE-2026-74870
was published
Aug 17, 2026
ProTip!
Advisories are also available from the
GraphQL API