GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,586
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,571 advisories
Filter by severity
Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...
High
Unreviewed
CVE-2026-103263
was published
Oct 1, 2026
Tornado: StaticFileHandler follows symlinks outside static root (path traversal)
High
GHSA-c2m8-h5v5-343r
was published
for
tornado
(pip)
Sep 30, 2026
Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log...
Moderate
Unreviewed
CVE-2026-81310
was published
Sep 30, 2026
@xhmikosr/decompress: Path traversal via symlink chain
Critical
CVE-2026-101894
was published
for
@xhmikosr/decompress
(npm)
Sep 29, 2026
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path...
High
Unreviewed
CVE-2026-92371
was published
Sep 29, 2026
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata...
High
Unreviewed
CVE-2026-100838
was published
Sep 27, 2026
Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data...
Critical
Unreviewed
CVE-2026-100716
was published
Sep 26, 2026
Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP...
High
Unreviewed
CVE-2026-100715
was published
Sep 26, 2026
Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js...
High
Unreviewed
CVE-2026-100690
was published
Sep 26, 2026
Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink...
High
Unreviewed
CVE-2026-100692
was published
Sep 26, 2026
gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree...
High
Unreviewed
CVE-2026-100419
was published
Sep 26, 2026
Improper Link Resolution Before File Access in the drag source staging path of the drag and drop...
Moderate
Unreviewed
CVE-2026-80430
was published
Sep 25, 2026
copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows...
Moderate
Unreviewed
CVE-2026-93353
was published
Sep 24, 2026
Improper link resolution before file access ('link following') vulnerability in the `tar` source...
Critical
Unreviewed
CVE-2026-82331
was published
Sep 23, 2026
Improper link resolution before file access in the quarantine restoration process of WatchDog...
Moderate
Unreviewed
CVE-2026-92253
was published
Sep 20, 2026
pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD,...
Moderate
Unreviewed
CVE-2026-86861
was published
Sep 17, 2026
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
High
CVE-2026-85731
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution...
Low
Unreviewed
CVE-2026-71181
was published
Sep 16, 2026
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution...
Low
Unreviewed
CVE-2026-71182
was published
Sep 16, 2026
An insufficient check allowed for the overwrite of arbitrary files via a symlink.
Critical
Unreviewed
CVE-2026-68491
was published
Sep 15, 2026
A flaw was found in the containers/storage library. A crafted tar archive containing a malicious...
Moderate
Unreviewed
CVE-2026-79699
was published
Sep 15, 2026
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when...
Critical
Unreviewed
CVE-2026-77179
was published
Sep 15, 2026
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Golden...
High
Unreviewed
CVE-2026-84584
was published
Sep 14, 2026
In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable...
High
Unreviewed
CVE-2026-82049
was published
Sep 14, 2026
A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function...
Low
Unreviewed
CVE-2026-90807
was published
Sep 14, 2026
ProTip!
Advisories are also available from the
GraphQL API