GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
167 advisories
Filter by severity
Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker...
High
Unreviewed
CVE-2026-106252
was published
Oct 6, 2026
proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
Critical
CVE-2026-90711
was published
for
proxy-addr
(npm)
Oct 5, 2026
In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport...
Moderate
Unreviewed
CVE-2026-71892
was published
Oct 3, 2026
ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
Moderate
CVE-2026-101912
was published
for
ip-address
(npm)
Sep 29, 2026
ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
Moderate
CVE-2026-101913
was published
for
ip-address
(npm)
Sep 28, 2026
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
Moderate
CVE-2026-79913
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function...
Low
Unreviewed
CVE-2026-93957
was published
Sep 20, 2026
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation
Moderate
CVE-2026-61795
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
High
CVE-2026-61672
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the...
Moderate
Unreviewed
CVE-2026-90977
was published
Sep 18, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure...
High
Unreviewed
CVE-2026-20333
was published
Sep 16, 2026
evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist...
Moderate
Unreviewed
CVE-2026-91997
was published
Sep 15, 2026
Affected versions of MISP incorrectly filter dashboard templates that are restricted to a...
Moderate
Unreviewed
CVE-2026-91851
was published
Sep 15, 2026
OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the...
Moderate
Unreviewed
CVE-2026-56101
was published
Sep 8, 2026
XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token...
Critical
Unreviewed
CVE-2026-73309
was published
Sep 8, 2026
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is...
Critical
Unreviewed
CVE-2026-75110
was published
Aug 17, 2026
Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3:...
Moderate
Unreviewed
CVE-2026-20765
was published
Aug 11, 2026
Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in...
High
Unreviewed
CVE-2026-67207
was published
Jul 30, 2026
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
High
CVE-2026-55771
was published
for
com.cedarpolicy:cedar-java
(Maven)
Jul 28, 2026
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
Moderate
CVE-2026-59890
was published
for
setuptools
(pip)
Jul 21, 2026
A vulnerability was found in HdrHistogram up to 2.2.2. This issue affects the function org...
Low
Unreviewed
CVE-2026-14686
was published
Jul 5, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
High
CVE-2026-49340
was published
for
go.senan.xyz/gonic
(Go)
Jun 26, 2026
js-toml has silent type confusion via falsy-primitive duplicate-key bypass
Moderate
CVE-2026-50029
was published
for
js-toml
(npm)
Jun 26, 2026
ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2...
Moderate
Unreviewed
CVE-2026-10097
was published
Jun 25, 2026
@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers
High
CVE-2026-48032
was published
for
@hulumi/policies
(npm)
Jun 10, 2026
ProTip!
Advisories are also available from the
GraphQL API