GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
15,029 advisories
Filter by severity
s2n-quic has excessive memory allocation
Moderate
CVE-2026-10740
was published
for
s2n-quic
(Rust)
Aug 14, 2026
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
Moderate
CVE-2026-55156
was published
for
@ooples/token-optimizer-mcp
(npm)
Aug 14, 2026
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Moderate
CVE-2026-53708
was published
for
mcp-contextforge-gateway
(pip)
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
Moderate
GHSA-8rw6-p7m8-63jp
was published
for
surrealdb
(Rust)
Aug 14, 2026
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Moderate
CVE-2026-53658
was published
for
github.com/hyperledger/fabric-ca
(Go)
Aug 14, 2026
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
Moderate
CVE-2026-53722
was published
for
nuxt
(npm)
Jun 16, 2026
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
Moderate
CVE-2026-56326
was published
for
nuxt
(npm)
Jun 16, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Moderate
CVE-2026-55590
was published
for
cakephp/authentication
(Composer)
Jun 17, 2026
Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations
Moderate
CVE-2026-53442
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"
Moderate
CVE-2026-53440
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Jenkins exposes other users' timezone and view names to users with Overall/Read permission
Moderate
CVE-2026-53439
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Jenkins: Missing permission check allows unauthorized cancellation of queue items
Moderate
CVE-2026-53438
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL
Moderate
CVE-2026-53437
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Moderate
CVE-2026-73419
was published
for
@auth/core
(npm)
Jul 23, 2026
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Moderate
CVE-2026-64607
was published
for
org.apache.httpcomponents.client5:httpclient5
(Maven)
Jul 31, 2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Moderate
CVE-2026-73559
was published
for
vllm
(pip)
Aug 13, 2026
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization
Moderate
CVE-2026-49844
was published
for
org.apache.logging.log4j:log4j-api
(Maven)
Jul 11, 2026
Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL
Moderate
CVE-2026-53436
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
TypeORM: migration:generate template-literal code injection
Moderate
CVE-2026-73651
was published
for
typeorm
(npm)
Jul 21, 2026
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Moderate
CVE-2026-73648
was published
for
rails-html-sanitizer
(RubyGems)
Jul 21, 2026
Quasar: Prototype pollution in the extend() utility
Moderate
CVE-2026-73647
was published
for
quasar
(npm)
Jul 24, 2026
ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds.
Moderate
CVE-2026-73645
was published
for
@openzeppelin/confidential-contracts
(npm)
Jan 5, 2026
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
Moderate
CVE-2026-73565
was published
for
@hono/node-server
(npm)
Jul 21, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
Moderate
CVE-2026-52815
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
Moderate
CVE-2026-73563
was published
for
@backstage/plugin-auth-backend
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API