GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
43 advisories
Filter by severity
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
Low
GHSA-rf68-8gjr-36q7
was published
for
github.com/nezhahq/nezha
(Go)
Sep 15, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
Low
CVE-2026-42350
was published
for
github.com/akuity/kargo
(Go)
Aug 27, 2026
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
Low
CVE-2026-55403
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
Low
CVE-2026-59730
was published
for
@astrojs/node
(npm)
Jul 20, 2026
Waku has an Open Redirect via `unstable_redirect` Helper
Low
CVE-2026-49456
was published
for
waku
(npm)
Jul 8, 2026
Concourse login flow has an open redirect issue
Low
CVE-2026-49826
was published
for
github.com/concourse/concourse
(Go)
Jul 1, 2026
hsweb-framework has an open redirect issue
Low
CVE-2026-11477
was published
for
org.hswebframework.web:hsweb-authorization-oauth2
(Maven)
Jun 8, 2026
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login
Low
CVE-2026-48589
was published
for
org.apache.shiro:shiro-jakarta-ee
(Maven)
May 26, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint
Low
GHSA-7qx6-f23w-3w7f
was published
for
github.com/patrickhener/goshs
(Go)
Apr 14, 2026
Kimai has an Open Redirect via Unvalidated RelayState in SAML ACS Handler
Low
GHSA-3jp4-mhh4-gcgr
was published
for
kimai/kimai
(Composer)
Apr 14, 2026
Casdoor vulnerable to Open Redirect
Low
CVE-2026-5467
was published
for
github.com/casdoor/casdoor
(Go)
Apr 3, 2026
AVideo has an Open Redirect via Unvalidated redirectUri in userLogin.php
Low
CVE-2026-33296
was published
for
wwbn/avideo
(Composer)
Mar 19, 2026
Qwik City Open Redirect via fixTrailingSlash
Low
CVE-2026-25149
was published
for
@builder.io/qwik-city
(npm)
Feb 3, 2026
Moodle Open Redirect vulnerability
Low
CVE-2025-67852
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Mattermost has missing redirect URL validation
Low
CVE-2025-62690
was published
for
github.com/mattermost/mattermost
(Go)
Dec 17, 2025
Mayan EDMS has an Open Redirect through the /authentication/ file
Low
CVE-2025-14692
was published
for
mayan-edms
(pip)
Dec 15, 2025
Open redirect endpoint in Datasette
Low
CVE-2025-64481
was published
for
datasette
(pip)
Nov 6, 2025
Byaidu PDFMathTranslate vulnerable to open redirect
Low
CVE-2025-50736
was published
for
pdf2zh
(pip)
Oct 30, 2025
reflex-dev/reflex has an Open Redirect vulnerability
Low
CVE-2025-62379
was published
for
reflex
(pip)
Oct 15, 2025
Mattermost Open Redirect vulnerability
Low
CVE-2025-9084
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
Koa Open Redirect via Referrer Header (User-Controlled)
Low
CVE-2025-8129
was published
for
koa
(npm)
Jul 29, 2025
Duplicate Advisory: Koa Open Redirect via Referrer Header (User-Controlled)
Low
GHSA-mvw6-62qv-vmqf
was published
for
koa
(npm)
Jul 25, 2025
•
withdrawn
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
Low
CVE-2025-53535
was published
for
better-auth
(npm)
Jul 7, 2025
XXL SSO is vulnerable to an Open Redirect through malicious manipulation of the redirect_url argument
Low
CVE-2025-6701
was published
for
com.xuxueli:xxl-sso
(Maven)
Jun 26, 2025
@misskey-dev/summaly Redirect Filter Bypass
Low
CVE-2025-46553
was published
for
@misskey-dev/summaly
(npm)
May 5, 2025
ProTip!
Advisories are also available from the
GraphQL API