GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,857
Maven
5,000+
npm
4,488
NuGet
780
pip
4,243
Pub
12
RubyGems
975
Rust
1,095
Swift
49
Unreviewed advisories
All unreviewed
5,000+
3,583 advisories
Filter by severity
HTTP Request Smuggling: Content-Length Sent Twice in Waitress
Critical
CVE-2019-16792
was published
for
waitress
(pip)
Dec 20, 2019
com.enonic.xp:lib-auth vulnerable to Session Fixation
Critical
CVE-2024-23679
was published
for
com.enonic.xp:lib-auth
(Maven)
Oct 12, 2022
Duplicate Advisory: Session fixation in Enonic XP
Critical
GHSA-4hrp-m3f2-643j
was published
for
com.enonic.xp:lib-auth
(Maven)
Jan 19, 2024
•
withdrawn
Duplicate Advisory: Consensys gnark-crypto allows Signature Malleability
Critical
GHSA-9xfq-8j3r-xp5g
was published
for
github.com/Consensys/gnark-crypto
(Go)
Sep 28, 2023
•
withdrawn
Ecto missing `is_nil` requirement
Critical
CVE-2017-20166
was published
for
ecto
(Erlang)
Apr 12, 2022
Duplicate Advisory: Ecto lacks a protection mechanism
Critical
GHSA-4r2f-6fm9-2qgh
was published
for
ecto
(Erlang)
Jan 10, 2023
•
withdrawn
Hard-coded System User Credentials in Folio Data Export Spring module
Critical
CVE-2024-23687
was published
for
org.folio:mod-data-export-spring
(Maven)
Jul 25, 2023
Duplicate Advisory: Hard-coded credentials in org.folio:mod-data-export-spring
Critical
GHSA-9rhq-86fm-qxqc
was published
for
org.folio:mod-data-export-spring
(Maven)
Jan 20, 2024
•
withdrawn
OpenShift GitOps authenticated attackers can obtain cluster root access through forged ArgoCD custom resources
Critical
CVE-2025-13888
was published
for
github.com/redhat-developer/gitops-operator
(Go)
Dec 15, 2025
WeKnora has Command Injection in MCP stdio test
Critical
CVE-2026-22688
was published
for
github.com/Tencent/WeKnora
(Go)
Jan 9, 2026
sm-crypto Affected by Private Key Recovery in SM2-PKE
Critical
CVE-2026-23966
was published
for
sm-crypto
(npm)
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
Critical
CVE-2026-23524
was published
for
laravel/reverb
(Composer)
Jan 21, 2026
Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment
Critical
CVE-2026-23518
was published
for
github.com/fleetdm/fleet
(Go)
Jan 20, 2026
External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function
Critical
CVE-2026-22822
was published
for
github.com/external-secrets/external-secrets
(Go)
Jan 20, 2026
Langflow CORS misconfiguration enables Account Takeover and RCE
Critical
CVE-2025-34291
was published
for
langflow
(pip)
Dec 6, 2025
Salesforce Uni2TS has a Code Injection vulnerability
Critical
CVE-2026-22584
was published
for
uni2ts
(pip)
Jan 10, 2026
Orval has a code injection via unsanitized x-enum-descriptions in enum generation
Critical
CVE-2026-23947
was published
for
@orval/core
(npm)
Jan 21, 2026
XDocReport affected by an XML External Entity (XXE) vulnerability
Critical
CVE-2025-65482
was published
for
fr.opensagres.xdocreport:fr.opensagres.xdocreport.document
(Maven)
Jan 20, 2026
XDocReport affected by a Server-Side Template Injection (SSTI) vulnerability
Critical
CVE-2025-64087
was published
for
fr.opensagres.xdocreport:fr.opensagres.xdocreport.template.freemarker
(Maven)
Jan 20, 2026
Fleet has SAML authentication vulnerability due to improper SAML response validation
Critical
CVE-2025-27509
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 6, 2025
Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests
Critical
CVE-2025-12543
was published
for
io.undertow:undertow-core
(Maven)
Jan 7, 2026
flat vulnerable to Prototype Pollution
Critical
CVE-2020-36632
was published
for
flat
(npm)
Dec 25, 2022
BackendAI Missing Authentication for Critical Function
Critical
CVE-2025-49652
was published
for
backend.ai
(pip)
Jun 9, 2025
REC in MCPJam inspector due to HTTP Endpoint exposes
Critical
CVE-2026-23744
was published
for
@mcpjam/inspector
(npm)
Jan 16, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
Critical
CVE-2025-68924
was published
for
UmbracoForms
(NuGet)
Jan 13, 2026
ProTip!
Advisories are also available from the
GraphQL API