GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
40 advisories
Filter by severity
Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint...
High
Unreviewed
CVE-2026-32993
was published
May 14, 2026
Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM...
High
Unreviewed
CVE-2026-5140
was published
Apr 29, 2026
PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes
High
GHSA-mh6w-vxff-9wqp
was published
for
phpunit/phpunit
(Composer)
Apr 22, 2026
PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes
High
CVE-2026-41570
was published
for
phpunit/phpunit
(Composer)
Apr 18, 2026
MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing...
High
Unreviewed
CVE-2026-6351
was published
Apr 16, 2026
Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()
High
CVE-2026-41230
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands
High
GHSA-6v7q-wjvx-w8wg
was published
for
basic-ftp
(npm)
Apr 10, 2026
basic-ftp has FTP Command Injection via CRLF
High
CVE-2026-39983
was published
for
basic-ftp
(npm)
Apr 8, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
High
CVE-2026-39394
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields
High
CVE-2026-33128
was published
for
h3
(npm)
Mar 18, 2026
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution...
High
Unreviewed
CVE-2026-1714
was published
Feb 18, 2026
Incus container environment configuration newline injection
High
CVE-2026-23953
was published
for
github.com/lxc/incus/v6
(Go)
Jan 22, 2026
ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler
High
CVE-2026-22777
was published
for
comfy-cli
(pip)
Jan 13, 2026
Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
High
CVE-2025-59419
was published
for
io.netty:netty-codec-smtp
(Maven)
Oct 15, 2025
A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute...
High
Unreviewed
CVE-2025-28357
was published
Oct 1, 2025
Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server...
High
Unreviewed
CVE-2025-8715
was published
Aug 14, 2025
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1...
High
Unreviewed
CVE-2025-41376
was published
Aug 1, 2025
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi...
High
Unreviewed
CVE-2025-6175
was published
Jul 29, 2025
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported...
High
Unreviewed
CVE-2024-53693
was published
Mar 7, 2025
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported...
High
Unreviewed
CVE-2024-48868
was published
Dec 6, 2024
A CRLF cross-site scripting vulnerability has been identified in certain configurations of the...
High
Unreviewed
CVE-2024-36459
was published
Jun 14, 2024
A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high...
High
Unreviewed
CVE-2023-38551
was published
May 31, 2024
The software does not neutralize or incorrectly neutralizes certain characters before the data is...
High
Unreviewed
CVE-2024-1226
was published
Mar 12, 2024
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an...
High
Unreviewed
CVE-2024-20337
was published
Mar 6, 2024
Async HTTP Client has CRLF Injection vulnerability in HTTP request headers
High
CVE-2023-0040
was published
for
github.com/swift-server/async-http-client
(Swift)
Jun 7, 2023
ProTip!
Advisories are also available from the
GraphQL API