GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
724 advisories
Filter by severity
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout
Moderate
CVE-2026-107804
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment
Critical
CVE-2026-108261
was published
for
@tinacms/app
(npm)
Oct 9, 2026
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
High
CVE-2026-61435
was published
for
praisonai
(pip)
Oct 8, 2026
Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header
Moderate
CVE-2026-107292
was published
for
pydantic-ai
(pip)
Oct 8, 2026
Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpoint
High
CVE-2026-107295
was published
for
pydantic-ai
(pip)
Oct 8, 2026
AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins
High
CVE-2026-107230
was published
for
org.asynchttpclient:async-http-client
(Maven)
Oct 8, 2026
Missing Host header validation and missing throttling of failed administrator sign-ins in the...
High
Unreviewed
CVE-2026-104659
was published
Oct 8, 2026
Next.js has information disclosure in development server's Model Context Protocol endpoint
Low
CVE-2026-94486
was published
for
next
(npm)
Oct 7, 2026
Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass
Moderate
CVE-2026-94485
was published
for
next
(npm)
Oct 7, 2026
Payload external upload trust validation issue
High
CVE-2026-105861
was published
for
payload
(npm)
Oct 7, 2026
Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path
Critical
CVE-2026-103922
was published
for
@capacitor/android
(Maven)
Oct 5, 2026
Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that...
Moderate
Unreviewed
CVE-2026-105396
was published
Oct 5, 2026
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
Low
CVE-2026-74802
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery ...
Moderate
Unreviewed
CVE-2026-102588
was published
Sep 30, 2026
mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP...
High
Unreviewed
CVE-2026-102878
was published
Sep 29, 2026
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
High
CVE-2026-85152
was published
for
undici
(npm)
Sep 29, 2026
Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
High
CVE-2026-102673
was published
for
electron
(npm)
Sep 29, 2026
Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
High
CVE-2026-102675
was published
for
electron
(npm)
Sep 29, 2026
Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR...
High
Unreviewed
CVE-2026-100830
was published
Sep 29, 2026
Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in...
Moderate
Unreviewed
CVE-2026-100821
was published
Sep 29, 2026
Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox...
High
Unreviewed
CVE-2026-100816
was published
Sep 29, 2026
Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR...
High
Unreviewed
CVE-2026-100809
was published
Sep 29, 2026
Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox...
High
Unreviewed
CVE-2026-100803
was published
Sep 29, 2026
An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker...
Moderate
Unreviewed
CVE-2026-18825
was published
Sep 28, 2026
SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in...
High
Unreviewed
CVE-2026-100642
was published
Sep 26, 2026
ProTip!
Advisories are also available from the
GraphQL API