Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,246 advisories

Loading
Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling High
CVE-2026-56817 was published for io.netty:netty-codec-xml (Maven) Jul 22, 2026
dyingman1 Credited to dyingman1
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247 Low
GHSA-8678-w3jw-xfc2 was published for nokogiri (RubyGems) Jun 19, 2026
bilerden Credited to bilerden
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory Critical
CVE-2026-55471 was published for ca.uhn.hapi.fhir:org.hl7.fhir.utilities (Maven) Jun 17, 2026
GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution Moderate
CVE-2025-58175 was published for org.geoserver.web:gs-web-app (Maven) Jun 12, 2026
lemauanhphong Credited to lemauanhphong and jodygarnett jodygarnett jodygarnett
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a... Critical Unreviewed
CVE-2026-49875 was published Jun 12, 2026
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend High
CVE-2026-44020 was published for docling (pip) Jun 3, 2026
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend Moderate
CVE-2026-44018 was published for docling (pip) Jun 3, 2026
brodmart Credited to brodmart
Symfony has XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true Low
CVE-2026-45071 was published for symfony/dom-crawler (Composer) May 27, 2026
ProTip! Advisories are also available from the GraphQL API