GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
3,990
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,390
Swift
56
Unreviewed advisories
All unreviewed
5,000+
31,491 advisories
Filter by severity
@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
Moderate
CVE-2026-48037
was published
for
@hulumi/baseline
(npm)
Jun 10, 2026
@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
High
CVE-2026-48036
was published
for
@hulumi/drift
(npm)
Jun 10, 2026
@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened
High
CVE-2026-48035
was published
for
@hulumi/baseline
(npm)
Jun 10, 2026
@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
High
CVE-2026-48034
was published
for
@hulumi/policies
(npm)
Jun 10, 2026
@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name
High
CVE-2026-48033
was published
for
@hulumi/policies
(npm)
Jun 10, 2026
@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers
High
CVE-2026-48032
was published
for
@hulumi/policies
(npm)
Jun 10, 2026
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter
Critical
CVE-2026-48030
was published
for
pheditor/pheditor
(Composer)
Jun 9, 2026
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
High
GHSA-7qjx-gp9h-65qj
was published
for
github.com/dexidp/dex
(Go)
Jun 9, 2026
PhoenixStorybook has cross-session PubSub topic injection via URL parameter
Low
CVE-2026-47068
was published
for
phoenix_storybook
(Erlang)
Jun 9, 2026
PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)
High
CVE-2026-8469
was published
for
phoenix_storybook
(Erlang)
Jun 9, 2026
PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
Critical
CVE-2026-8467
was published
for
phoenix_storybook
(Erlang)
Jun 9, 2026
SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch
Moderate
CVE-2026-47767
was published
for
symfony/runtime
(Composer)
Jun 9, 2026
Net::IMAP: Command Injection via ID command argument
Moderate
CVE-2026-47242
was published
for
net-imap
(RubyGems)
Jun 9, 2026
Net::IMAP: Denial of Service via incomplete raw argument validation
Low
CVE-2026-47241
was published
for
net-imap
(RubyGems)
Jun 9, 2026
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
Moderate
CVE-2026-47240
was published
for
net-imap
(RubyGems)
Jun 9, 2026
shell-quote quote() does not escape newlines in object .op values
Critical
CVE-2026-9277
was published
for
shell-quote
(npm)
Jun 9, 2026
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
High
CVE-2026-47737
was published
for
puma
(RubyGems)
Jun 9, 2026
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
High
CVE-2026-47736
was published
for
puma
(RubyGems)
Jun 8, 2026
Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks
High
CVE-2026-47735
was published
for
github.com/basekick-labs/arc
(Go)
Jun 8, 2026
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
Moderate
CVE-2026-47734
was published
for
dulwich
(pip)
Jun 8, 2026
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
High
CVE-2026-47726
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 8, 2026
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints
High
CVE-2026-47725
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 8, 2026
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation
Critical
CVE-2026-47724
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 8, 2026
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
High
CVE-2026-47723
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 8, 2026
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml
High
CVE-2026-47722
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 8, 2026
ProTip!
Advisories are also available from the
GraphQL API