GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
169 advisories
Filter by severity
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
Moderate
GHSA-fj2x-mqqp-3v2w
was published
for
trigger.dev
(npm)
Oct 2, 2026
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
Moderate
GHSA-hjwh-xvfw-qrwj
was published
for
mcp-searxng
(npm)
Aug 19, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors
Moderate
CVE-2026-55102
was published
for
hashi-vault-js
(npm)
Aug 13, 2026
Apache Airflow bulk endpoints log Variable and Connection secrets in cleartext
Moderate
CVE-2026-68969
was published
for
apache-airflow
(pip)
Aug 12, 2026
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Moderate
CVE-2026-54704
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Moderate
CVE-2026-65589
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Moderate
GHSA-fmvg-vhqq-r2mj
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
Moderate
CVE-2026-59947
was published
for
composer/composer
(Composer)
Jul 20, 2026
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
Moderate
GHSA-q683-8468-r6h6
was published
for
web-auth/webauthn-symfony-bundle
(Composer)
Jun 26, 2026
foreman-mcp-server Inserts Sensitive Information into Log File
Moderate
CVE-2026-9073
was published
for
foreman-mcp-server
(pip)
Jun 23, 2026
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
Moderate
CVE-2026-54236
was published
for
vllm
(pip)
Jun 17, 2026
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
Moderate
CVE-2026-47768
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 10, 2026
Admidio writes session IDs and auto-login cookie values to application logs
Moderate
CVE-2026-47234
was published
for
admidio/admidio
(Composer)
May 29, 2026
Calico Inserts Sensitive Information into Log File
Moderate
CVE-2026-41184
was published
for
github.com/projectcalico/calico
(Go)
May 28, 2026
Calico Inserts Sensitive Information into Log File
Moderate
CVE-2026-41185
was published
for
github.com/projectcalico/calico
(Go)
May 28, 2026
OpenBao's Inline Auth Incorrectly Redacted Headers
Moderate
CVE-2026-46358
was published
for
github.com/openbao/openbao
(Go)
May 28, 2026
Setup PHP: GitHub tokens configured by setup-php may be exposed through pinned affected Composer versions
Moderate
GHSA-5wxr-w449-57cm
was published
for
shivammathur/setup-php
(GitHub Actions)
May 20, 2026
fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
Moderate
CVE-2026-45581
was published
for
org.hyperledger.fabric-chaincode-java:fabric-chaincode-shim
(Maven)
May 19, 2026
OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
Moderate
CVE-2026-45679
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
Apache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URL
Moderate
CVE-2026-43826
was published
for
apache-airflow-providers-opensearch
(pip)
May 11, 2026
Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL
Moderate
CVE-2026-41018
was published
for
apache-airflow-providers-elasticsearch
(pip)
May 11, 2026
Spring Cloud Config Server Logged Sensitive Information
Moderate
CVE-2026-41004
was published
for
org.springframework.cloud:spring-cloud-config-server
(Maven)
May 7, 2026
Vercel: Non-interactive mode includes CLI arguments in suggested command output
Moderate
CVE-2026-44479
was published
for
vercel
(npm)
May 7, 2026
n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode
Moderate
CVE-2026-42282
was published
for
n8n-mcp
(npm)
Apr 25, 2026
n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests
Moderate
CVE-2026-41495
was published
for
n8n-mcp
(npm)
Apr 23, 2026
ProTip!
Advisories are also available from the
GraphQL API