GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,857
Maven
5,000+
npm
4,488
NuGet
780
pip
4,243
Pub
12
RubyGems
975
Rust
1,095
Swift
49
Unreviewed advisories
All unreviewed
5,000+
8,907 advisories
Filter by severity
Incus container image templating arbitrary host file read and write
High
CVE-2026-23954
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
Jan 22, 2026
Incus container environment configuration newline injection
High
CVE-2026-23953
was published
for
github.com/lxc/incus/v6
(Go)
Jan 22, 2026
Sentencepiece has a a heap overflow issue
High
CVE-2026-1260
was published
for
sentencepiece
(pip)
Jan 22, 2026
Orval Mock Generation Code Injection via const
High
CVE-2026-24132
was published
for
@orval/mock
(npm)
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
GHSA-3v2x-9xcv-2v2v
was published
for
surrealdb
(Rust)
Jan 22, 2026
Dragonfly Manager Job API Unauthenticated Access
High
CVE-2026-24124
was published
for
d7y.io/dragonfly/v2
(Go)
Jan 22, 2026
Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack
High
CVE-2026-24049
was published
for
wheel
(pip)
Jan 22, 2026
docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
High
CVE-2026-24009
was published
for
docling-core
(pip)
Jan 22, 2026
Seroval affected by Denial of Service via Deeply Nested Objects
High
CVE-2026-24006
was published
for
seroval
(npm)
Jan 22, 2026
Typebot affected by Credential Theft via Client-Side Script Execution and API Authorization Bypass
High
CVE-2025-65098
was published
for
@typebot.io/js
(npm)
Jan 22, 2026
Soft Serve Affected by an Authentication Bypass
High
CVE-2026-24058
was published
for
github.com/charmbracelet/soft-serve
(Go)
Jan 21, 2026
Wrangler affected by OS Command Injection in `wrangler pages deploy`
High
CVE-2026-0933
was published
for
wrangler
(npm)
Jan 21, 2026
Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
High
CVE-2026-24046
was published
for
@backstage/backend-defaults
(npm)
Jan 21, 2026
Argo Workflows affected by stored XSS in the artifact directory listing
High
CVE-2026-23960
was published
for
github.com/argoproj/argo-workflows
(Go)
Jan 21, 2026
Seroval affected by Denial of Service via Array serialization
High
CVE-2026-23957
was published
for
seroval
(npm)
Jan 21, 2026
seroval affected by Denial of Service via RegExp serialization
High
CVE-2026-23956
was published
for
seroval
(npm)
Jan 21, 2026
@envelop/graphql-modules has a Race Condition vulnerability
High
GHSA-h3hw-29fv-2x75
was published
for
@envelop/graphql-modules
(npm)
Jan 21, 2026
sm-crypto Affected by Signature Forgery in SM2-DSA
High
CVE-2026-23965
was published
for
sm-crypto
(npm)
Jan 21, 2026
sm-crypto Affected by Signature Malleability in SM2-DSA
High
CVE-2026-23967
was published
for
sm-crypto
(npm)
Jan 21, 2026
vLLM affected by RCE via auto_map dynamic module loading during model initialization
High
CVE-2026-22807
was published
for
vllm
(pip)
Jan 21, 2026
seroval Affected by Remote Code Execution via JSON Deserialization
High
CVE-2026-23737
was published
for
seroval
(npm)
Jan 21, 2026
seroval Affected by Prototype Pollution via JSON Deserialization
High
CVE-2026-23736
was published
for
seroval
(npm)
Jan 21, 2026
Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
High
CVE-2026-22022
was published
for
org.apache.solr:solr-core
(Maven)
Jan 21, 2026
Apache Solr: Insufficient file-access checking in standalone core-creation requests
High
CVE-2026-22444
was published
for
org.apache.solr:solr-core
(Maven)
Jan 21, 2026
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
High
CVE-2026-23950
was published
for
tar
(npm)
Jan 21, 2026
ProTip!
Advisories are also available from the
GraphQL API