GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
21 advisories
Filter by severity
URL Redirection to Untrusted Site ('Open Redirect') in express-openid-connect
High
CVE-2022-24794
was published
for
express-openid-connect
(npm)
Mar 31, 2022
oauth2-server through 3.1.1 vulnerable to Open Redirect
High
CVE-2020-26938
was published
for
oauth2-server
(npm)
Aug 30, 2022
DOS and Open Redirect with user input
High
CVE-2021-22964
was published
for
fastify-static
(npm)
Oct 12, 2021
node-fetch forwards secure headers to untrusted sites
High
CVE-2022-0235
was published
for
node-fetch
(npm)
Jan 21, 2022
@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass
High
CVE-2024-34065
was published
for
@strapi/plugin-users-permissions
(npm)
Jun 12, 2024
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
High
CVE-2024-56734
was published
for
better-auth
(npm)
Dec 30, 2024
Authentication bypass in @sap/approuter
High
CVE-2025-24876
was published
for
@sap/approuter
(npm)
Feb 11, 2025
Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
High
GHSA-vp58-j275-797x
was published
for
better-auth
(npm)
Feb 24, 2025
Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains
High
CVE-2026-24052
was published
for
@anthropic-ai/claude-code
(npm)
Feb 3, 2026
Feathers has an open redirect in OAuth callback enables account takeover
High
CVE-2026-27191
was published
for
@feathersjs/authentication-oauth
(npm)
Feb 19, 2026
Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects
High
GHSA-pg8g-f2hf-x82m
was published
for
openclaw
(npm)
Apr 9, 2026
•
withdrawn
Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click
High
CVE-2026-43941
was published
for
electerm
(npm)
May 8, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
High
CVE-2026-40171
was published
for
@jupyter-notebook/help-extension
(npm)
Apr 30, 2026
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
High
CVE-2026-55660
was published
for
@tinacms/app
(npm)
Jun 19, 2026
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
High
GHSA-86j7-9j95-vpqj
was published
for
better-auth
(npm)
Jul 7, 2026
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
High
CVE-2026-53728
was published
for
@medplum/core
(npm)
Aug 17, 2026
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
High
CVE-2026-44503
was published
for
Microsoft.Kiota.Abstractions
(Go)
May 7, 2026
SAP Approuter has an Open Redirect vulnerability
High
CVE-2026-44745
was published
for
@sap/approuter
(npm)
Jul 14, 2026
SAP Approuter has an Information Disclosure vulnerability
High
CVE-2026-58230
was published
for
@sap/approuter
(npm)
Aug 11, 2026
Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
High
CVE-2026-101907
was published
for
axios
(npm)
Sep 30, 2026
ProTip!
Advisories are also available from the
GraphQL API