GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
917 advisories
Filter by severity
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
GHSA-p279-2cqp-84jg
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Critical
GHSA-68r5-9hpg-7qw9
was published
for
org.openidentityplatform.opendj:opendj-dsml-servlet
(Maven)
Jul 24, 2026
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
Critical
CVE-2026-62379
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Jul 24, 2026
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
Critical
CVE-2026-62263
was published
for
org.openidentityplatform.openam:openam-auth-webauthn
(Maven)
Jul 24, 2026
fastjson has a remote code execution (RCE) vulnerability
Critical
CVE-2026-16723
was published
for
com.alibaba:fastjson
(Maven)
Jul 23, 2026
Apache Camel: KeycloakSecurityPolicy has Improper Authentication, Missing Authentication for Critical Function and Failing Open Vulnerabilities
Critical
CVE-2026-53913
was published
for
org.apache.camel:camel-keycloak
(Maven)
Jul 6, 2026
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF)
Critical
CVE-2026-48205
was published
for
org.apache.camel:camel-dns
(Maven)
Jul 6, 2026
Apache Camel: camel-mongodb-gridfs producer allows GridFS operation override and NoSQL operator injection via unfiltered gridfs.* HTTP headers
Critical
CVE-2026-48204
was published
for
org.apache.camel:camel-mongodb-gridfs
(Maven)
Jul 6, 2026
LaunchServer FileServerHandler has an unauthenticated path traversal issue
Critical
CVE-2026-54617
was published
for
pro.gravit.launcher:launchserver-api
(Maven)
Jul 2, 2026
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints
Critical
CVE-2026-45052
was published
for
org.openidentityplatform.openam:openam-federation-library
(Maven)
Jun 24, 2026
OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage
Critical
CVE-2026-45051
was published
for
org.openidentityplatform.openam:openam-auth-webauthn
(Maven)
Jun 24, 2026
OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI
Critical
CVE-2026-46495
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jun 22, 2026
OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)
Critical
CVE-2026-44203
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jun 22, 2026
xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro
Critical
CVE-2026-44179
was published
for
com.xwiki.pro:xwiki-pro-macros
(Maven)
Jun 22, 2026
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
Critical
CVE-2026-57168
was published
for
io.openremote:openremote-manager
(Maven)
Jun 19, 2026
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
Critical
CVE-2026-55471
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.utilities
(Maven)
Jun 17, 2026
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
Critical
CVE-2026-32966
was published
for
org.apache.dolphinscheduler:dolphinscheduler-api
(Maven)
Jun 17, 2026
Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
Critical
CVE-2026-32967
was published
for
org.apache.dolphinscheduler:dolphinscheduler-api
(Maven)
Jun 17, 2026
Apache Fory Java SDK Has Deserialization of Untrusted Data in the Java replace-resolve path
Critical
CVE-2026-50076
was published
for
org.apache.fory:fory-core
(Maven)
Jun 4, 2026
Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass
Critical
CVE-2026-47065
was published
for
org.apache.mina:mina-core
(Maven)
Jun 3, 2026
Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
Critical
CVE-2026-46621
was published
for
org.yamcs:yamcs-core
(Maven)
May 27, 2026
Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override
Critical
CVE-2026-46562
was published
for
org.yamcs:yamcs-core
(Maven)
May 27, 2026
Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
Critical
CVE-2026-44632
was published
for
org.yamcs:yamcs-core
(Maven)
May 27, 2026
XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}
Critical
CVE-2026-33137
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
May 26, 2026
XWiki Platform has path traversal via resources parameter in ssx and jsx endpoints when using leading slash
Critical
CVE-2026-23734
was published
for
org.xwiki.commons:xwiki-commons-classloader-api
(Maven)
May 26, 2026
ProTip!
Advisories are also available from the
GraphQL API