GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
168 advisories
Filter by severity
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
Moderate
GHSA-w253-m66g-rx24
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 8, 2026
Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules
Moderate
GHSA-3wr7-993q-jrff
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 8, 2026
Coraza has Cookie Parser Confusion
Moderate
GHSA-g4qm-m288-5cp9
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 8, 2026
Coraza: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations
Moderate
CVE-2026-107825
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 8, 2026
Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection
Moderate
GHSA-5gj4-9gm7-2fx2
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 8, 2026
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
High
CVE-2026-106505
was published
for
@backstage/plugin-techdocs-node
(npm)
Oct 7, 2026
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
High
GHSA-9c5c-9qcx-q35q
was published
for
@nestjs/platform-fastify
(npm)
Sep 30, 2026
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
Moderate
CVE-2026-86818
was published
for
fast-uri
(npm)
Sep 29, 2026
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
Moderate
GHSA-g57g-f23g-4646
was published
for
nodemailer
(npm)
Sep 29, 2026
adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
Moderate
GHSA-p634-w6r4-rjp2
was published
for
adm-zip
(npm)
Sep 29, 2026
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
High
CVE-2026-84394
was published
for
fast-uri
(npm)
Sep 28, 2026
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
High
CVE-2026-56669
was published
for
elysia
(npm)
Sep 23, 2026
http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches(...
High
Unreviewed
CVE-2026-93750
was published
Sep 18, 2026
Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib...
High
Unreviewed
CVE-2026-92597
was published
Sep 17, 2026
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain...
High
Unreviewed
CVE-2026-92598
was published
Sep 17, 2026
A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the...
Low
Unreviewed
CVE-2026-91835
was published
Sep 15, 2026
Traefik entrypoint header-name sanitization bypassed via request trailers
High
CVE-2026-88004
was published
for
github.com/traefik/traefik/v3
(Go)
Sep 10, 2026
Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed...
Moderate
Unreviewed
CVE-2026-87627
was published
Sep 9, 2026
Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to...
High
Unreviewed
CVE-2026-82537
was published
Sep 8, 2026
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
Moderate
GHSA-wmmp-3585-3rmp
was published
for
nodemailer
(npm)
Sep 8, 2026
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
Moderate
GHSA-cc9r-2j5m-2m83
was published
for
nodemailer
(npm)
Sep 8, 2026
Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a...
High
Unreviewed
CVE-2026-81378
was published
Sep 8, 2026
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
Moderate
CVE-2026-73846
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 3, 2026
Mail: Email address spoofing via malformed RFC 2047 encoded-words
Moderate
CVE-2026-63435
was published
for
mail
(RubyGems)
Sep 2, 2026
ProTip!
Advisories are also available from the
GraphQL API