GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
13,406 advisories
Filter by severity
pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination
Moderate
CVE-2026-48484
was published
for
pyload-ng
(pip)
Oct 9, 2026
Improper input validation vulnerability in Apache Camel Karavan.
When a deployment was started...
High
Unreviewed
CVE-2026-103413
was published
Oct 9, 2026
Hazelcast allows arbitrary member memory access by low-privileged client
Critical
CVE-2026-107726
was published
for
com.hazelcast:hazelcast
(Maven)
Oct 8, 2026
Banks: User-controlled prompt input can be parsed as privileged chat messages
Moderate
CVE-2026-107717
was published
for
banks
(pip)
Oct 8, 2026
fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set
High
CVE-2026-107720
was published
for
fast-jwt
(npm)
Oct 8, 2026
PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
High
CVE-2026-61427
was published
for
praisonai
(pip)
Oct 8, 2026
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
Moderate
GHSA-w253-m66g-rx24
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 8, 2026
Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules
Moderate
GHSA-3wr7-993q-jrff
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 8, 2026
Coraza: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations
Moderate
CVE-2026-107825
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 8, 2026
Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection
Moderate
GHSA-5gj4-9gm7-2fx2
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 8, 2026
Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP...
Moderate
Unreviewed
CVE-2026-88257
was published
Oct 8, 2026
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not validate that a wallet...
Moderate
Unreviewed
CVE-2026-93509
was published
Oct 8, 2026
An Improper Input Validation vulnerability for the registered case credentials in Brocade ASCG...
Moderate
Unreviewed
CVE-2023-5649
was published
Oct 8, 2026
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role...
Moderate
Unreviewed
CVE-2026-76277
was published
Oct 7, 2026
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role...
Moderate
Unreviewed
CVE-2026-76279
was published
Oct 7, 2026
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role...
Moderate
Unreviewed
CVE-2026-76273
was published
Oct 7, 2026
Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml
Moderate
CVE-2026-107225
was published
for
github.com/xuri/excelize/v2
(Go)
Oct 7, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS...
High
Unreviewed
CVE-2026-76456
was published
Oct 7, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco...
High
Unreviewed
CVE-2026-76468
was published
Oct 7, 2026
MISP contains a validation flaw in its object synchronization logic. When a MISP Object is...
Moderate
Unreviewed
CVE-2026-107278
was published
Oct 7, 2026
WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE
High
CVE-2026-106443
was published
for
WeasyPrint
(pip)
Oct 7, 2026
Backstage: Improper entity validation in deprecated Kubernetes services endpoint
Moderate
CVE-2026-106563
was published
for
@backstage/plugin-kubernetes-backend
(npm)
Oct 7, 2026
Backstage: Improper input validation in proxy-backend
Moderate
CVE-2026-106491
was published
for
@backstage/plugin-proxy-backend
(npm)
Oct 7, 2026
The CakeResponse::download() method in lib/Cake/Network/CakeResponse.php constructs a Content...
High
Unreviewed
CVE-2026-106512
was published
Oct 6, 2026
Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a...
Critical
Unreviewed
CVE-2026-106414
was published
Oct 6, 2026
ProTip!
Advisories are also available from the
GraphQL API