GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,193
Erlang
25
GitHub Actions
39
Go
2,385
Maven
3,027
npm
3,078
NuGet
529
pip
2,897
Pub
5
RubyGems
442
Rust
905
Swift
20
Unreviewed advisories
All unreviewed
5,000+
176 advisories
Filter by severity
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
High
CVE-2026-41066
was published
for
lxml
(pip)
Apr 21, 2026
OpenRemote has XXE in Velbus Asset Import
High
CVE-2026-40882
was published
for
io.openremote:openremote-manager
(Maven)
Apr 15, 2026
Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability
High
CVE-2026-26171
was published
for
System.Security.Cryptography.Xml
(NuGet)
Apr 14, 2026
esaml XXE vulnerability allows local file disclosure and SSRF via crafted SAML messages
Moderate
CVE-2026-28809
was published
for
esaml
(Erlang)
Mar 23, 2026
Apache Syncope: Console XXE on Keymaster parameters
Moderate
CVE-2026-23795
was published
for
org.apache.syncope.client.idrepo:syncope-client-idrepo-console
(Maven)
Feb 3, 2026
AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion
High
CVE-2026-24400
was published
for
org.assertj:assertj-core
(Maven)
Jan 26, 2026
XDocReport affected by an XML External Entity (XXE) vulnerability
Critical
CVE-2025-65482
was published
for
fr.opensagres.xdocreport:fr.opensagres.xdocreport.document
(Maven)
Jan 20, 2026
Apache Struts 2 is Missing XML Validation
High
CVE-2025-68493
was published
for
com.opensymphony:xwork
(Maven)
Jan 11, 2026
Bio-Formats has an XML External Entity (XXE) vulnerability
Moderate
CVE-2026-22186
was published
for
ome:pom-bio-formats
(Maven)
Jan 7, 2026
Apache SIS has Improper Restriction of XML External Entity Reference vulnerability
Moderate
CVE-2025-68280
was published
for
org.apache.sis.core:sis-metadata
(Maven)
Jan 5, 2026
Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
Moderate
CVE-2025-68463
was published
for
biopython
(pip)
Dec 18, 2025
Apache Tika has XXE vulnerability
Critical
CVE-2025-66516
was published
for
org.apache.tika:tika-core
(Maven)
Dec 4, 2025
Peppol-py is vulnerable to XXE attacks due to Saxon configuration
Moderate
CVE-2025-66371
was published
for
peppol_py
(pip)
Nov 28, 2025
Mustangproject allows exfiltrating files via XXE attacks
Low
CVE-2025-66372
was published
for
org.mustangproject:library
(Maven)
Nov 28, 2025
GeoServer is vulnerable to Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
High
CVE-2025-58360
was published
for
org.geoserver.web:gs-web-app
(Maven)
Nov 25, 2025
CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection
High
CVE-2025-64518
was published
for
org.cyclonedx:cyclonedx-core-java
(Maven)
Nov 10, 2025
WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks
Moderate
CVE-2025-10713
was published
for
org.wso2.carbon.mediation:org.wso2.carbon.localentry
(Maven)
Nov 5, 2025
Jenkins JDepend Plugin vulnerable to XML external entity attacks
High
CVE-2025-64134
was published
for
org.jenkins-ci.plugins:jdepend
(Maven)
Oct 29, 2025
LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing
High
CVE-2025-6985
was published
for
langchain-text-splitters
(pip)
Oct 6, 2025
Langchain Community Vulnerable to XML External Entity (XXE) Attacks
High
CVE-2025-6984
was published
for
langchain-community
(pip)
Sep 4, 2025
Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
Critical
CVE-2025-54988
was published
for
org.apache.tika:tika-parser-pdf-module
(Maven)
Aug 20, 2025
DSpace is vulnerable to XML External Entity injection during archive imports
Moderate
CVE-2025-53621
was published
for
org.dspace:dspace-api
(Maven)
Jul 15, 2025
Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
High
CVE-2025-53689
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Jul 14, 2025
Allure Report allows Improper XXE Restriction via DocumentBuilderFactory
High
CVE-2025-52888
was published
for
io.qameta.allure.plugins:junit-xml-plugin
(Maven)
Jun 25, 2025
PowSyBl Core XML Reader allows XXE and SSRF
Low
CVE-2025-47293
was published
for
com.powsybl:powsybl-commons
(Maven)
Jun 19, 2025
ProTip!
Advisories are also available from the
GraphQL API