GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
31 advisories
Filter by severity
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
CVE-2026-43871
was published
for
apache/thrift
(Composer)
Jul 27, 2026
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
High
CVE-2026-66908
was published
for
org.apache.camel:camel-platform-http-main
(Maven)
Aug 24, 2026
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
High
CVE-2026-66907
was published
for
org.apache.camel:camel-google-storage
(Maven)
Aug 24, 2026
Apache Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy
High
CVE-2026-46726
was published
for
org.apache.camel:camel-vertx-websocket
(Maven)
Jul 6, 2026
Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters
High
CVE-2026-49042
was published
for
org.apache.camel:camel-langchain4j-agent
(Maven)
Jul 6, 2026
Apache Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy
High
CVE-2026-55993
was published
for
org.apache.camel:camel-atmosphere-websocket
(Maven)
Jul 6, 2026
Apache Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy
High
CVE-2026-55994
was published
for
org.apache.camel:camel-iggy
(Maven)
Jul 6, 2026
Apache Camel-CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
High
CVE-2026-46588
was published
for
org.apache.camel:camel-couchdb
(Maven)
Jul 6, 2026
Apache Camel-Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
High
CVE-2026-46587
was published
for
org.apache.camel:camel-couchbase
(Maven)
Jul 6, 2026
Apache Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
High
CVE-2026-46592
was published
for
org.apache.camel:camel-cxf-rest
(Maven)
Jul 6, 2026
Apache Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)
High
CVE-2026-46591
was published
for
org.apache.camel:camel-neo4j
(Maven)
Jul 6, 2026
Apache Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)
High
CVE-2026-46590
was published
for
org.apache.camel:camel-pqc
(Maven)
Jul 6, 2026
Apache Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
High
CVE-2026-46585
was published
for
org.apache.camel:camel-lucene
(Maven)
Jul 6, 2026
Apache Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
High
CVE-2026-46457
was published
for
org.apache.camel:camel-nats
(Maven)
Jul 6, 2026
Apache Camel JMS deserialization filter bypass
High
CVE-2026-43866
was published
for
org.apache.camel:camel-activemq
(Maven)
Jul 6, 2026
Apache Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution
High
CVE-2026-43865
was published
for
org.apache.camel:camel-hazelcast
(Maven)
Jul 6, 2026
Apache Camel-Vertx-Http and Camel-Netty-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
High
CVE-2026-40859
was published
for
org.apache.camel:camel-netty-http
(Maven)
Jul 6, 2026
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
High
CVE-2026-42527
was published
for
org.apache.camel:camel-amqp
(Maven)
Jul 6, 2026
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
High
CVE-2026-41731
was published
for
org.springframework.kafka:spring-kafka
(Maven)
Jun 10, 2026
Deserialization of Untrusted Data in Apache Camel CassandraQL
High
CVE-2024-23114
was published
for
org.apache.camel:camel-cassandraql
(Maven)
Feb 20, 2024
Deserialization of Untrusted Data in Apache Camel SQL
High
CVE-2024-22369
was published
for
org.apache.camel:camel-sql
(Maven)
Feb 20, 2024
SMTP smuggling in Apache James
High
CVE-2023-51747
was published
for
org.apache.james:james-server
(Maven)
Feb 27, 2024
Apache Ambari: authenticated users could perform command injection to perform RCE
High
CVE-2023-50379
was published
for
org.apache.ambari.contrib.views:ambari-contrib-views
(Maven)
Feb 27, 2024
Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated
High
CVE-2024-22234
was published
for
org.springframework.security:spring-security-core
(Maven)
Feb 20, 2024
Apache Linkis Spark EngineConn: Commons Lang's RandomStringUtils Random string security vulnerability
High
CVE-2024-39928
was published
for
org.apache.linkis:linkis-engineplugin-spark
(Maven)
Sep 25, 2024
ProTip!
Advisories are also available from the
GraphQL API