GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,967
Maven
5,000+
npm
5,000+
NuGet
973
pip
5,000+
Pub
13
RubyGems
1,064
Rust
1,387
Swift
56
Unreviewed advisories
All unreviewed
5,000+
555 advisories
Filter by severity
A Dag author could either (a) create a symlink under their task's log directory pointing to an...
Moderate
Unreviewed
CVE-2026-40861
was published
Jun 1, 2026
Sparkle: Binary delta apply intermediate-symlink traversal in malicious .delta
Moderate
CVE-2026-47121
was published
for
github.com/sparkle-project/Sparkle
(Swift)
May 29, 2026
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8...
Moderate
Unreviewed
CVE-2026-6891
was published
May 29, 2026
Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may...
Moderate
Unreviewed
CVE-2026-6892
was published
May 29, 2026
FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via...
Moderate
Unreviewed
CVE-2026-48693
was published
May 26, 2026
An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell...
Moderate
Unreviewed
CVE-2026-34883
was published
May 19, 2026
HashiCorp Nomad vulnerable to symlink attack
Moderate
CVE-2026-6959
was published
for
github.com/hashicorp/nomad
(Go)
May 12, 2026
HashiCorp Nomad’s exec2 task driver vulnerable to a symlink attack
Moderate
CVE-2026-8052
was published
for
github.com/hashicorp/nomad-driver-exec2
(Go)
May 12, 2026
The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the...
Moderate
Unreviewed
CVE-2026-5061
was published
May 12, 2026
BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
Moderate
CVE-2026-40610
was published
for
bentoml
(pip)
May 7, 2026
A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part...
Moderate
Unreviewed
CVE-2026-7832
was published
May 5, 2026
Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution...
Moderate
Unreviewed
CVE-2026-27105
was published
Apr 29, 2026
Spring Boot's PID file write follows symlinks at predictable default path
Moderate
CVE-2026-40977
was published
for
org.springframework.boot:spring-boot-cassandra
(Maven)
Apr 28, 2026
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that...
Moderate
Unreviewed
CVE-2026-6941
was published
Apr 23, 2026
uutils coreutils has a Link Following Issue Via rm Utility
Moderate
CVE-2026-35349
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has a Link Following issue
Moderate
CVE-2026-35359
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has a Link Following issue
Moderate
CVE-2026-35365
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has a Link Following Issue
Moderate
CVE-2026-35345
was published
for
coreutils
(Rust)
Apr 22, 2026
python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
Moderate
CVE-2026-28684
was published
for
python-dotenv
(pip)
Apr 21, 2026
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated,...
Moderate
Unreviewed
CVE-2026-20161
was published
Apr 15, 2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo...
Moderate
Unreviewed
CVE-2026-4135
was published
Apr 15, 2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo...
Moderate
Unreviewed
CVE-2026-0827
was published
Apr 15, 2026
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp...
Moderate
Unreviewed
CVE-2026-32212
was published
Apr 14, 2026
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in...
Moderate
Unreviewed
CVE-2026-32282
was published
Apr 8, 2026
Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape
Moderate
CVE-2026-34452
was published
for
anthropic
(pip)
Apr 1, 2026
ProTip!
Advisories are also available from the
GraphQL API