GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,562 advisories
Filter by severity
Directus has a DOM-Based cross-site scripting (XSS) via layout_options
Low
CVE-2024-6533
was published
for
directus
(npm)
Jan 23, 2025
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
Low
CVE-2026-73425
was published
for
@astrojs/netlify
(npm)
Jul 20, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Low
CVE-2026-73491
was published
for
loofah
(RubyGems)
Jul 21, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
CVE-2026-73427
was published
for
action_text-trix
(RubyGems)
Mar 29, 2026
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
Low
CVE-2026-59730
was published
for
@astrojs/node
(npm)
Jul 20, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Low
CVE-2026-59727
was published
for
astro
(npm)
Jul 20, 2026
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads
Low
CVE-2026-41694
was published
for
org.springframework.security:spring-security-saml2-service-provider
(Maven)
Jun 10, 2026
Keras: tar extraction permits symlink-based path traversal
Low
CVE-2026-12482
was published
for
keras
(pip)
Jul 14, 2026
Django: signed cookies are vulnerable to salt namespace collisions
Low
CVE-2026-6873
was published
for
django
(pip)
Jun 3, 2026
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
Low
CVE-2026-8404
was published
for
django
(pip)
Jun 3, 2026
Django: cache middleware may expose private responses when unrelated request cookies are present
Low
CVE-2026-48588
was published
for
django
(pip)
Jul 7, 2026
Django: has_vary_header may expose cached responses when Vary values contain whitespace
Low
CVE-2026-48587
was published
for
django
(pip)
Jun 3, 2026
Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
Low
CVE-2026-35193
was published
for
django
(pip)
Jun 3, 2026
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
Low
CVE-2026-71849
was published
for
hono
(npm)
Aug 7, 2026
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Low
CVE-2026-71847
was published
for
json
(RubyGems)
Aug 7, 2026
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
Low
CVE-2026-56394
was published
for
craftcms/cms
(Composer)
Jul 9, 2026
Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
Low
CVE-2026-56385
was published
for
craftcms/cms
(Composer)
Mar 26, 2026
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options
Low
CVE-2026-56393
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page
Low
CVE-2026-56381
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
Craft CMS: Incorrect path validation could potentially lead to path traversal
Low
GHSA-7hxc-f267-h5q7
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type
Low
CVE-2026-56383
was published
for
craftcms/cms
(Composer)
Feb 25, 2026
Mermaid configuration APIs allow prototype pollution
Low
CVE-2026-71438
was published
for
mermaid
(npm)
Aug 6, 2026
Contao: Possible path traversal in job download URIs
Low
CVE-2026-55825
was published
for
contao/contao
(Composer)
Aug 6, 2026
Contao crawler leaks auth credentials to external hosts
Low
CVE-2026-55824
was published
for
contao/contao
(Composer)
Aug 6, 2026
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Low
CVE-2026-71326
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
ProTip!
Advisories are also available from the
GraphQL API