GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
107 advisories
Filter by severity
Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability
Critical
CVE-2026-65182
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 26, 2026
Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability
Critical
CVE-2026-68525
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 26, 2026
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability
Critical
CVE-2026-65905
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 26, 2026
Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
Critical
CVE-2026-78329
was published
for
org.apache.camel:camel-undertow
(Maven)
Aug 24, 2026
Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
Moderate
CVE-2026-60093
was published
for
org.apache.camel:camel-azure-storage-datalake
(Maven)
Aug 24, 2026
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
High
CVE-2026-66907
was published
for
org.apache.camel:camel-google-storage
(Maven)
Aug 24, 2026
Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
Moderate
CVE-2026-63621
was published
for
org.apache.camel:camel-knative
(Maven)
Aug 24, 2026
Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
Critical
CVE-2026-66906
was published
for
org.apache.camel:camel-azure-storage-blob
(Maven)
Aug 24, 2026
Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection - the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace
Critical
CVE-2026-71300
was published
for
org.apache.camel:camel-atmosphere-websocket
(Maven)
Aug 24, 2026
Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
Moderate
CVE-2026-59230
was published
for
org.apache.camel:camel-mail
(Maven)
Aug 24, 2026
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
High
CVE-2026-66908
was published
for
org.apache.camel:camel-platform-http-main
(Maven)
Aug 24, 2026
Apache Ranger has a Command Injection vulnerability
Critical
CVE-2026-28672
was published
for
org.apache.ranger:ranger
(Maven)
Aug 10, 2026
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
Moderate
CVE-2026-66053
was published
for
thrift
(pip)
Jul 27, 2026
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
High
CVE-2026-41608
was published
for
thrift
(pip)
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
CVE-2026-43871
was published
for
apache/thrift
(Composer)
Jul 27, 2026
Apache Camel-Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
High
CVE-2026-46587
was published
for
org.apache.camel:camel-couchbase
(Maven)
Jul 6, 2026
Apache Camel-CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
High
CVE-2026-46588
was published
for
org.apache.camel:camel-couchdb
(Maven)
Jul 6, 2026
Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters
High
CVE-2026-49042
was published
for
org.apache.camel:camel-langchain4j-agent
(Maven)
Jul 6, 2026
Apache Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body
Moderate
CVE-2026-56139
was published
for
org.apache.camel:camel-undertow
(Maven)
Jul 6, 2026
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF)
Critical
CVE-2026-48205
was published
for
org.apache.camel:camel-dns
(Maven)
Jul 6, 2026
Apache Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy
Critical
CVE-2026-56140
was published
for
org.apache.camel:camel-aws2-sns
(Maven)
Jul 6, 2026
Apache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter
Moderate
CVE-2026-48206
was published
for
org.apache.camel:camel-jira
(Maven)
Jul 6, 2026
Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter
Moderate
CVE-2026-49099
was published
for
org.apache.camel:camel-salesforce
(Maven)
Jul 6, 2026
Apache Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body
Moderate
CVE-2026-49365
was published
for
org.apache.camel:camel-netty-http
(Maven)
Jul 6, 2026
Apache Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers
Moderate
CVE-2026-49086
was published
for
org.apache.camel:camel-dapr
(Maven)
Jul 6, 2026
ProTip!
Advisories are also available from the
GraphQL API