GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
54 advisories
Filter by severity
Vikunja: Link-share principal-type confusion enables cross-account team removal, bot takeover, and roster disclosure
High
CVE-2026-76216
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
pyLoad WindowsPhoneNotify addon: non-admin SETTINGS user triggers SSRF via unguarded http.client notification host
Moderate
GHSA-p3pr-8f3m-4qp8
was published
for
pyload-ng
(pip)
Oct 9, 2026
AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompression-bomb denial of service when compression is enabled
High
CVE-2026-107227
was published
for
org.asynchttpclient:async-http-client
(Maven)
Oct 8, 2026
Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_method
High
CVE-2026-106440
was published
for
hydra-optuna-sweeper
(pip)
Oct 7, 2026
Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
High
CVE-2026-102600
was published
for
@socket.io/cluster-engine
(npm)
Oct 5, 2026
vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
Critical
CVE-2026-92934
was published
for
vm2
(npm)
Oct 5, 2026
Langflow: Unauthenticated Flow Execution via Webhook Authentication Bypass
Critical
CVE-2026-8505
was published
for
langflow
(pip)
Oct 5, 2026
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path
Moderate
CVE-2026-59944
was published
for
composer/composer
(Composer)
Oct 2, 2026
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
High
GHSA-8w8g-wq8h-fq33
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
High
GHSA-5fqc-mrg8-w798
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks
High
GHSA-cm62-gvxx-vmxx
was published
for
dulwich
(pip)
Oct 2, 2026
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
High
CVE-2026-92958
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
Critical
CVE-2026-92957
was published
for
vm2
(npm)
Oct 1, 2026
GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing
High
CVE-2026-87819
was published
for
GitPython
(pip)
Sep 30, 2026
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
Moderate
CVE-2026-86818
was published
for
fast-uri
(npm)
Sep 29, 2026
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
High
CVE-2026-19534
was published
for
undici
(npm)
Sep 29, 2026
Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
High
CVE-2026-102675
was published
for
electron
(npm)
Sep 29, 2026
deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
High
CVE-2026-63116
was published
for
@deepstream/server
(npm)
Sep 22, 2026
Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
High
CVE-2026-75837
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
High
CVE-2026-81516
was published
for
Steeltoe.Discovery.Consul
(NuGet)
Sep 17, 2026
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
High
CVE-2026-81515
was published
for
Steeltoe.Discovery.Eureka
(NuGet)
Sep 17, 2026
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
Moderate
CVE-2026-75523
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Sep 17, 2026
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
Moderate
CVE-2026-85732
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
Moderate
CVE-2026-88016
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
High
CVE-2026-87995
was published
for
open-webui
(pip)
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API