GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
113 advisories
Filter by severity
Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False`
Low
CVE-2026-107293
was published
for
pydantic-ai
(pip)
Oct 8, 2026
Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False`
Low
CVE-2026-107291
was published
for
pydantic-ai
(pip)
Oct 8, 2026
Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia...
Moderate
Unreviewed
CVE-2026-96879
was published
Sep 25, 2026
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00...
Low
Unreviewed
CVE-2026-17511
was published
Sep 24, 2026
The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an...
High
Unreviewed
CVE-2026-90860
was published
Sep 21, 2026
HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when...
Moderate
Unreviewed
CVE-2026-67071
was published
Sep 17, 2026
On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP)...
Low
Unreviewed
CVE-2026-73440
was published
Sep 16, 2026
Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in...
Moderate
Unreviewed
CVE-2026-86740
was published
Sep 9, 2026
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability
Moderate
CVE-2026-62900
was published
for
Microsoft.Build.Tasks.Git
(NuGet)
Sep 8, 2026
A security issue in MongoDB Server's query statistics serialization on the router allows users...
Moderate
Unreviewed
CVE-2026-82069
was published
Sep 8, 2026
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM...
Moderate
Unreviewed
CVE-2026-78658
was published
Sep 4, 2026
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin...
High
Unreviewed
CVE-2026-85094
was published
Sep 4, 2026
An access control bypass and information disclosure vulnerability exists in the base AppArmor...
Moderate
Unreviewed
CVE-2024-5300
was published
Jul 21, 2026
A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management....
Moderate
Unreviewed
CVE-2026-15811
was published
Jul 21, 2026
Guzzle: URI fragments disclosed in redirect Referer headers
Moderate
CVE-2026-67354
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
A flaw was found in the authentication configuration endpoint of the keycloak-services component,...
Moderate
Unreviewed
CVE-2026-16104
was published
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
High
CVE-2026-53604
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
Moderate
CVE-2026-54421
was published
for
ironic
(pip)
Jun 14, 2026
The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic...
Moderate
Unreviewed
CVE-2026-36178
was published
Jun 4, 2026
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
Moderate
CVE-2026-45737
was published
for
github.com/argoproj/argo-cd/v3
(Go)
May 19, 2026
Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content
Moderate
CVE-2026-45046
was published
for
github.com/safedep/gryph
(Go)
May 11, 2026
FacturaScripts Vulnerable to Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/Download
Moderate
CVE-2026-27892
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
A low privileged remote attacker can gain the root password due to improper removal of sensitive...
High
Unreviewed
CVE-2024-43384
was published
May 7, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
Critical
CVE-2026-42880
was published
for
github.com/argoproj/argo-cd/v3
(Go)
May 7, 2026
OpenBao's Namespace Deletion May Not Delete Data Properly
Low
CVE-2026-42186
was published
for
github.com/openbao/openbao
(Go)
May 5, 2026
ProTip!
Advisories are also available from the
GraphQL API