GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
74
GitHub Actions
54
Go
4,134
Maven
5,000+
npm
5,000+
NuGet
1,013
pip
5,000+
Pub
13
RubyGems
1,095
Rust
1,419
Swift
61
Unreviewed advisories
All unreviewed
5,000+
3,625 advisories
Filter by severity
golang.org/x/crypto/ssh: Invoking VerifiedPublicKeyCallback permissions skip enforcement
Critical
CVE-2026-46595
was published
for
golang.org/x/crypto/ssh
(Go)
Jun 25, 2026
Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id>
Moderate
CVE-2026-55163
was published
for
lemur
(pip)
Jun 25, 2026
ImageMagick: Policy Bypass can read disallowed files via symlink
Moderate
CVE-2026-49219
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission
High
CVE-2026-48508
was published
for
lemur
(pip)
Jun 25, 2026
LangGraph SDK has unsafe URL path construction
Moderate
CVE-2026-48776
was published
for
langgraph-sdk
(pip)
Jun 25, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6,...
Moderate
Unreviewed
CVE-2026-5796
was published
Jun 25, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0...
Low
Unreviewed
CVE-2026-0934
was published
Jun 25, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6,...
Moderate
Unreviewed
CVE-2026-11379
was published
Jun 25, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6,...
Moderate
Unreviewed
CVE-2026-5952
was published
Jun 25, 2026
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
High
CVE-2026-48507
was published
for
snipe/snipe-it
(Composer)
Jun 23, 2026
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
Moderate
CVE-2026-48493
was published
for
snipe/snipe-it
(Composer)
Jun 23, 2026
jackson-databind has @JsonView bypass for setterless creator properties
Moderate
CVE-2026-54517
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
jackson-databind has a @JsonView bypass for unwrapped creator parameters
Moderate
CVE-2026-54518
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration...
Moderate
Unreviewed
CVE-2026-56694
was published
Jun 23, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API
High
CVE-2026-52808
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when...
Low
Unreviewed
CVE-2026-8823
was published
Jun 22, 2026
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission...
Low
Unreviewed
CVE-2026-8074
was published
Jun 22, 2026
Authorization handling for component configuration verification requests in Apache NiFi 1.15.0...
Low
Unreviewed
CVE-2026-44911
was published
Jun 22, 2026
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
Moderate
GHSA-hv6h-hc26-q48p
was published
for
surrealdb
(Rust)
Jun 19, 2026
stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
High
GHSA-6gqw-jqv7-v88m
was published
for
stigmem-node
(pip)
Jun 19, 2026
stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
High
GHSA-xhv3-q4xx-349r
was published
for
stigmem-node
(pip)
Jun 19, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected
Low
CVE-2026-55866
was published
for
github.com/authzed/spicedb
(Go)
Jun 19, 2026
OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808
Low
CVE-2026-55774
was published
for
github.com/openbao/openbao
(Go)
Jun 19, 2026
containerd CRI checkpoint restore CDI annotation smuggling
High
CVE-2026-53492
was published
for
github.com/containerd/containerd/v2
(Go)
Jun 19, 2026
parse-server: Server option routeAllowList is bypassable through batch sub-requests
Moderate
CVE-2026-50008
was published
for
parse-server
(npm)
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API