GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
72 advisories
Filter by severity
In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport...
Moderate
Unreviewed
CVE-2026-71892
was published
Oct 3, 2026
ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
Moderate
CVE-2026-101912
was published
for
ip-address
(npm)
Sep 29, 2026
ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
Moderate
CVE-2026-101913
was published
for
ip-address
(npm)
Sep 28, 2026
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
Moderate
CVE-2026-79913
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation
Moderate
CVE-2026-61795
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the...
Moderate
Unreviewed
CVE-2026-90977
was published
Sep 18, 2026
evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist...
Moderate
Unreviewed
CVE-2026-91997
was published
Sep 15, 2026
Affected versions of MISP incorrectly filter dashboard templates that are restricted to a...
Moderate
Unreviewed
CVE-2026-91851
was published
Sep 15, 2026
OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the...
Moderate
Unreviewed
CVE-2026-56101
was published
Sep 8, 2026
Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3:...
Moderate
Unreviewed
CVE-2026-20765
was published
Aug 11, 2026
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
Moderate
CVE-2026-59890
was published
for
setuptools
(pip)
Jul 21, 2026
js-toml has silent type confusion via falsy-primitive duplicate-key bypass
Moderate
CVE-2026-50029
was published
for
js-toml
(npm)
Jun 26, 2026
ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2...
Moderate
Unreviewed
CVE-2026-10097
was published
Jun 25, 2026
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
Moderate
CVE-2026-35040
was published
for
fast-jwt
(npm)
Apr 9, 2026
Parse Server has a session field immutability bypass via falsy-value guard
Moderate
CVE-2026-34574
was published
for
parse-server
(npm)
Apr 1, 2026
mppx has Stripe charge credential replay via missing idempotency check
Moderate
CVE-2026-34210
was published
for
mppx
(npm)
Mar 29, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
Moderate
CVE-2026-32322
was published
for
soroban-sdk
(Rust)
Mar 13, 2026
The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up...
Moderate
Unreviewed
CVE-2025-12192
was published
Nov 5, 2025
Dragonfly vulnerable to timing attacks against Proxy’s basic authentication
Moderate
CVE-2025-59350
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by...
Moderate
Unreviewed
CVE-2025-47416
was published
Sep 9, 2025
A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of...
Moderate
Unreviewed
CVE-2025-9401
was published
Aug 25, 2025
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could...
Moderate
Unreviewed
CVE-2025-27909
was published
Aug 18, 2025
`idna` accepts Punycode labels that do not produce any non-ASCII when decoded
Moderate
CVE-2024-12224
was published
for
idna
(Rust)
Dec 9, 2024
When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's...
Moderate
Unreviewed
CVE-2024-9681
was published
Nov 6, 2024
An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks...
Moderate
Unreviewed
CVE-2024-39534
was published
Oct 11, 2024
ProTip!
Advisories are also available from the
GraphQL API