GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
40 advisories
Filter by severity
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11...
High
Unreviewed
CVE-2018-19585
was published
May 24, 2022
CRLF injection vulnerability in phpMyVisites before 2.2 allows remote attackers to inject...
High
Unreviewed
CVE-2007-0892
was published
May 1, 2022
A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote...
High
Unreviewed
CVE-2018-12477
was published
May 13, 2022
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
High
Unreviewed
CVE-2019-10678
was published
May 14, 2022
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed...
High
Unreviewed
CVE-2017-15400
was published
May 14, 2022
CRLF Injection in microweber
High
CVE-2022-0666
was published
for
microweber/microweber
(Composer)
Feb 19, 2022
Cachet vulnerable to new line injection during configuration edition
High
CVE-2021-39172
was published
for
cachethq/cachet
(Composer)
Aug 30, 2021
Async HTTP Client has CRLF Injection vulnerability in HTTP request headers
High
CVE-2023-0040
was published
for
github.com/swift-server/async-http-client
(Swift)
Jun 7, 2023
dio vulnerable to CRLF injection with HTTP method string
High
CVE-2021-31402
was published
for
dio
(Pub)
Mar 21, 2023
Duplicate Advisory: Improper Neutralization of CRLF Sequences in dio
High
GHSA-jwpw-q68h-r678
was published
for
dio
(Pub)
May 24, 2022
•
withdrawn
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an...
High
Unreviewed
CVE-2024-20337
was published
Mar 6, 2024
The software does not neutralize or incorrectly neutralizes certain characters before the data is...
High
Unreviewed
CVE-2024-1226
was published
Mar 12, 2024
cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923).
High
Unreviewed
CVE-2016-10803
was published
May 24, 2022
A CRLF cross-site scripting vulnerability has been identified in certain configurations of the...
High
Unreviewed
CVE-2024-36459
was published
Jun 14, 2024
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
CVE-2018-1000164
was published
for
gunicorn
(pip)
Jul 12, 2018
Kallithea CRLF injection vulnerability
High
CVE-2015-5285
was published
for
kallithea
(pip)
May 13, 2022
Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when...
High
Unreviewed
CVE-2023-26130
was published
May 30, 2023
bottle.py vulnerable to CRLF Injection
High
CVE-2016-9964
was published
for
bottle
(pip)
May 17, 2022
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported...
High
Unreviewed
CVE-2024-53693
was published
Mar 7, 2025
A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high...
High
Unreviewed
CVE-2023-38551
was published
May 31, 2024
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi...
High
Unreviewed
CVE-2025-6175
was published
Jul 29, 2025
Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server...
High
Unreviewed
CVE-2025-8715
was published
Aug 14, 2025
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported...
High
Unreviewed
CVE-2024-48868
was published
Dec 6, 2024
A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute...
High
Unreviewed
CVE-2025-28357
was published
Oct 1, 2025
Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
High
CVE-2025-59419
was published
for
io.netty:netty-codec-smtp
(Maven)
Oct 15, 2025
ProTip!
Advisories are also available from the
GraphQL API