GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,479
Maven
5,000+
npm
5,000+
NuGet
886
pip
4,740
Pub
13
RubyGems
1,031
Rust
1,225
Swift
53
Unreviewed advisories
All unreviewed
5,000+
50 advisories
Filter by severity
Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects
High
GHSA-pg8g-f2hf-x82m
was published
for
openclaw
(npm)
Apr 9, 2026
•
withdrawn
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri
High
GHSA-x3f4-v83f-7wp2
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint
High
CVE-2026-3872
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
Pocket ID: OAuth redirect_uri validation bypass via userinfo/host confusion
High
CVE-2026-28512
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Mar 9, 2026
IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email links
High
CVE-2026-28681
was published
for
irrd
(pip)
Mar 4, 2026
Feathers has an open redirect in OAuth callback enables account takeover
High
CVE-2026-27191
was published
for
@feathersjs/authentication-oauth
(npm)
Feb 19, 2026
NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write
High
CVE-2026-25732
was published
for
nicegui
(pip)
Feb 5, 2026
Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains
High
CVE-2026-24052
was published
for
@anthropic-ai/claude-code
(npm)
Feb 3, 2026
WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect
High
CVE-2025-68616
was published
for
weasyprint
(pip)
Jan 20, 2026
ZITADEL Vulnerable to Account Takeover Due to Improper Instance Validation in V2 Login
High
CVE-2026-29067
was published
for
github.com/zitadel/zitadel
(Go)
Dec 8, 2025
ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection
High
CVE-2025-64101
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
High
CVE-2025-6242
was published
for
vllm
(pip)
Oct 7, 2025
Mattermost Open Redirect vulnerability
High
CVE-2025-9072
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection
High
CVE-2025-48936
was published
for
github.com/zitadel/zitadel
(Go)
May 28, 2025
Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
High
GHSA-vp58-j275-797x
was published
for
better-auth
(npm)
Feb 24, 2025
Authentication bypass in @sap/approuter
High
CVE-2025-24876
was published
for
@sap/approuter
(npm)
Feb 11, 2025
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
High
CVE-2024-56734
was published
for
better-auth
(npm)
Dec 30, 2024
HAPI FHIR XML External Entity (XXE) vulnerability
High
CVE-2024-51132
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.convertors
(Maven)
Nov 5, 2024
Duplicate Advisory: Keycloak Open Redirect vulnerability
High
GHSA-vvf8-2h68-9475
was published
for
org.keycloak:keycloak-services
(Maven)
Sep 19, 2024
•
withdrawn
@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass
High
CVE-2024-34065
was published
for
@strapi/plugin-users-permissions
(npm)
Jun 12, 2024
Zendframework Remote Address Spoofing Vector in `Zend\Http\PhpEnvironment\RemoteAddress`
High
GHSA-xffp-6w68-4775
was published
for
zendframework/zendframework
(Composer)
Jun 7, 2024
silverstripe/framework BackURL validation bypass with malformed URLs
High
GHSA-m5q3-mvcr-gc5m
was published
for
silverstripe/framework
(Composer)
May 27, 2024
Silverstripe X-Forwarded-Host request hostname injection
High
GHSA-25gq-jvx2-vg9x
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Keycloak path traversal vulnerability in the redirect validation
High
CVE-2024-2419
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 17, 2024
Spring Framework URL Parsing with Host Validation
High
CVE-2024-22262
was published
for
org.springframework:spring-web
(Maven)
Apr 16, 2024
ProTip!
Advisories are also available from the
GraphQL API