GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
59 advisories
Filter by severity
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
Moderate
CVE-2026-71325
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator...
Critical
Unreviewed
CVE-2026-63071
was published
Jul 20, 2026
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator...
Critical
Unreviewed
CVE-2026-53421
was published
Jul 20, 2026
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator...
Critical
Unreviewed
CVE-2026-53405
was published
Jul 20, 2026
npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
High
CVE-2026-57135
was published
for
praisonai
(npm)
Jun 18, 2026
Sandbox escape due to incorrect boundary conditions in the Networking component. This...
Critical
Unreviewed
CVE-2026-12297
was published
Jun 16, 2026
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152,...
Critical
Unreviewed
CVE-2026-12295
was published
Jun 16, 2026
An attacker could cooperatively pass data from one secure GPU process to another secure GPU...
Moderate
Unreviewed
CVE-2026-41155
was published
Jun 13, 2026
Apache Syncope has an Improper Isolation or Compartmentalization vulnerability
High
CVE-2026-42782
was published
for
org.apache.syncope.core:syncope-core-spring
(Maven)
May 26, 2026
Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox...
High
Unreviewed
CVE-2026-8945
was published
May 19, 2026
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3.
Critical
Unreviewed
CVE-2026-8401
was published
May 12, 2026
Spring gRPC SecurityContext leaks across requests upon authorization failure
Moderate
CVE-2026-40968
was published
for
org.springframework.grpc:spring-grpc
(Maven)
Apr 28, 2026
Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding
Moderate
CVE-2026-41174
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
pretix: API leaks check-in data between events of the same organizer
Moderate
CVE-2026-5600
was published
for
pretix
(pip)
Apr 8, 2026
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
Moderate
CVE-2026-34775
was published
for
electron
(npm)
Apr 3, 2026
Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw
High
CVE-2026-4282
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
Keycloak: Replay of action tokens via improper handling of single-use entries
Moderate
CVE-2026-4325
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows...
High
Unreviewed
CVE-2025-12805
was published
Mar 27, 2026
Sandbox escape in the Responsive Design Mode component. This vulnerability affects Firefox < 149,...
Critical
Unreviewed
CVE-2026-4692
was published
Mar 24, 2026
ServiceNow has addressed a remote code execution vulnerability that was identified in the...
Critical
Unreviewed
CVE-2026-0542
was published
Feb 25, 2026
MCP Run Python has a Sandbox Escape & Server Takeover Vulnerability
Moderate
CVE-2026-25905
was published
for
mcp-run-python
(pip)
Feb 9, 2026
Due to a product misconfiguration in certain deployment types, it was possible from different...
High
Unreviewed
CVE-2025-53710
was published
Dec 18, 2025
An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5...
Moderate
Unreviewed
CVE-2025-46215
was published
Nov 18, 2025
When using the Grafana Databricks Datasource Plugin,
if Oauth passthrough is enabled on the...
Low
Unreviewed
CVE-2025-41116
was published
Nov 11, 2025
When using the Grafana Snowflake Datasource Plugin,
if Oauth passthrough is enabled on the...
Low
Unreviewed
CVE-2025-3717
was published
Nov 11, 2025
ProTip!
Advisories are also available from the
GraphQL API