GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
53 advisories
Filter by severity
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
High
CVE-2026-86049
was published
for
jupyter_server
(pip)
Sep 17, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
foreman-mcp-server Inserts Sensitive Information into Log File
Moderate
CVE-2026-9073
was published
for
foreman-mcp-server
(pip)
Jun 23, 2026
PGHoard: Password written to debug log
Low
CVE-2026-54711
was published
for
pghoard
(pip)
Jun 18, 2026
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
Moderate
CVE-2026-54236
was published
for
vllm
(pip)
Jun 17, 2026
dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
Low
CVE-2026-44969
was published
for
dbt-mcp
(pip)
May 14, 2026
Apache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URL
Moderate
CVE-2026-43826
was published
for
apache-airflow-providers-opensearch
(pip)
May 11, 2026
Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL
Moderate
CVE-2026-41018
was published
for
apache-airflow-providers-elasticsearch
(pip)
May 11, 2026
Apache Airflow: JWT token appearing in logs
Moderate
CVE-2026-31987
was published
for
apache-airflow
(pip)
Apr 16, 2026
LangSmith SDK: Streaming token events bypass output redaction
Moderate
CVE-2026-41182
was published
for
langsmith
(npm)
Apr 16, 2026
Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI
Moderate
CVE-2025-66236
was published
for
apache-airflow
(pip)
Apr 13, 2026
Apache Airflow exposes sensitive information in its log files
Moderate
CVE-2025-27555
was published
for
apache-airflow
(pip)
Feb 24, 2026
Llama Stack exposes secret in initialization log
Low
CVE-2026-25211
was published
for
llama-stack
(pip)
Jan 30, 2026
Apache Airflow proxy credentials for various providers might leak in task logs
High
CVE-2025-68675
was published
for
apache-airflow
(pip)
Jan 16, 2026
hermes's raw options logging may disclose secrets passed in via subcommand options argument
Moderate
CVE-2026-22798
was published
for
hermes
(pip)
Jan 13, 2026
Ansible Community General Collection is vulnerable to exposure of sensitive information
Moderate
CVE-2025-14010
was published
for
ansible
(pip)
Dec 4, 2025
ray vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-1979
was published
for
ray
(pip)
Mar 6, 2025
The Snowflake Connector for Python stores sensitive data in logs
Moderate
CVE-2024-49750
was published
for
snowflake-connector-python
(pip)
Oct 24, 2024
Ansible vulnerable to Insertion of Sensitive Information into Log File
High
CVE-2024-8775
was published
for
ansible-core
(pip)
Sep 16, 2024
Sensitive Information Exposure Through Insecure Logging For Secrets Like Metadata.DockerBuildArgs
Moderate
GHSA-rjc6-vm4h-85cg
was published
for
aws-sam-cli
(pip)
Sep 11, 2024
AWS SageMaker Training Toolkit logs CodeArtifact Authorization token
Moderate
GHSA-635v-pc42-fr74
was published
for
sagemaker-training
(pip)
Sep 11, 2024
ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command
Moderate
CVE-2024-41129
was published
for
ops
(pip)
Jul 22, 2024
Slack integration leaks sensitive information in logs
Low
CVE-2024-35196
was published
for
sentry
(pip)
Jun 2, 2024
Fides Webserver Logs Hosted Database Password Partial Exposure Vulnerability
Low
CVE-2024-34715
was published
for
ethyca-fides
(pip)
May 29, 2024
ProTip!
Advisories are also available from the
GraphQL API