GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
1,246 advisories
Filter by severity
Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling
High
CVE-2026-56817
was published
for
io.netty:netty-codec-xml
(Maven)
Jul 22, 2026
libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML...
Critical
Unreviewed
CVE-2026-51080
was published
Jul 17, 2026
Improper restriction of XML external entity reference vulnerability in Netcad Software Inc....
High
Unreviewed
CVE-2026-8396
was published
Jul 17, 2026
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ...
Critical
Unreviewed
CVE-2026-48359
was published
Jul 14, 2026
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of...
Moderate
Unreviewed
CVE-2026-54470
was published
Jul 10, 2026
The input file does not need to be strictly in a structurally valid PDF format. Instead, after...
Moderate
Unreviewed
CVE-2026-57259
was published
Jul 8, 2026
OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
High
CVE-2026-54640
was published
for
io.openremote:openremote-agent
(Maven)
Jul 6, 2026
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene...
Moderate
Unreviewed
CVE-2026-47898
was published
Jul 3, 2026
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML...
High
Unreviewed
CVE-2026-13449
was published
Jun 30, 2026
A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a...
High
Unreviewed
CVE-2026-12975
was published
Jun 26, 2026
Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file...
High
Unreviewed
CVE-2026-56701
was published
Jun 23, 2026
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
Low
GHSA-8678-w3jw-xfc2
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
Critical
CVE-2026-55471
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.utilities
(Maven)
Jun 17, 2026
GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
Moderate
CVE-2025-58175
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 12, 2026
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a...
Critical
Unreviewed
CVE-2026-49875
was published
Jun 12, 2026
Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a...
High
Unreviewed
CVE-2026-40998
was published
Jun 11, 2026
When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API...
Moderate
Unreviewed
CVE-2026-40991
was published
Jun 10, 2026
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML...
High
Unreviewed
CVE-2026-47960
was published
Jun 9, 2026
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could...
High
Unreviewed
CVE-2026-8045
was published
Jun 9, 2026
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
High
CVE-2026-44020
was published
for
docling
(pip)
Jun 3, 2026
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
Moderate
CVE-2026-44018
was published
for
docling
(pip)
Jun 3, 2026
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
Low
Unreviewed
CVE-2026-49383
was published
May 29, 2026
Symfony has XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
Low
CVE-2026-45071
was published
for
symfony/dom-crawler
(Composer)
May 27, 2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0,...
High
Unreviewed
CVE-2026-2253
was published
May 27, 2026
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 is vulnerable to an XML external...
High
Unreviewed
CVE-2026-3603
was published
May 26, 2026
ProTip!
Advisories are also available from the
GraphQL API