GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
107 advisories
Filter by severity
Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability
Critical
CVE-2026-68525
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 26, 2026
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability
Critical
CVE-2026-65905
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 26, 2026
Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability
Critical
CVE-2026-65182
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 26, 2026
Apache Ranger has a Command Injection vulnerability
Critical
CVE-2026-28672
was published
for
org.apache.ranger:ranger
(Maven)
Aug 10, 2026
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
Moderate
CVE-2026-66053
was published
for
thrift
(pip)
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
CVE-2026-43871
was published
for
apache/thrift
(Composer)
Jul 27, 2026
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
High
CVE-2026-41608
was published
for
thrift
(pip)
Jul 27, 2026
Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
Critical
CVE-2026-78329
was published
for
org.apache.camel:camel-undertow
(Maven)
Aug 24, 2026
Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection - the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace
Critical
CVE-2026-71300
was published
for
org.apache.camel:camel-atmosphere-websocket
(Maven)
Aug 24, 2026
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
High
CVE-2026-66908
was published
for
org.apache.camel:camel-platform-http-main
(Maven)
Aug 24, 2026
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
High
CVE-2026-66907
was published
for
org.apache.camel:camel-google-storage
(Maven)
Aug 24, 2026
Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
Critical
CVE-2026-66906
was published
for
org.apache.camel:camel-azure-storage-blob
(Maven)
Aug 24, 2026
Apache Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy
High
CVE-2026-46726
was published
for
org.apache.camel:camel-vertx-websocket
(Maven)
Jul 6, 2026
Apache Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
Critical
CVE-2026-48203
was published
for
org.apache.camel:camel-solr
(Maven)
Jul 6, 2026
Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
Moderate
CVE-2026-63621
was published
for
org.apache.camel:camel-knative
(Maven)
Aug 24, 2026
Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
Moderate
CVE-2026-60093
was published
for
org.apache.camel:camel-azure-storage-datalake
(Maven)
Aug 24, 2026
Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
Moderate
CVE-2026-59230
was published
for
org.apache.camel:camel-mail
(Maven)
Aug 24, 2026
Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters
High
CVE-2026-49042
was published
for
org.apache.camel:camel-langchain4j-agent
(Maven)
Jul 6, 2026
Apache Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers
Moderate
CVE-2026-49086
was published
for
org.apache.camel:camel-dapr
(Maven)
Jul 6, 2026
Apache Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter
Moderate
CVE-2026-49098
was published
for
org.apache.camel:camel-kafka
(Maven)
Jul 6, 2026
Apache Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter
Moderate
CVE-2026-49097
was published
for
org.apache.camel:camel-irc
(Maven)
Jul 6, 2026
Apache Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body
Moderate
CVE-2026-49365
was published
for
org.apache.camel:camel-netty-http
(Maven)
Jul 6, 2026
Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter
Moderate
CVE-2026-49099
was published
for
org.apache.camel:camel-salesforce
(Maven)
Jul 6, 2026
Apache Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy
High
CVE-2026-55993
was published
for
org.apache.camel:camel-atmosphere-websocket
(Maven)
Jul 6, 2026
Apache Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy
High
CVE-2026-55994
was published
for
org.apache.camel:camel-iggy
(Maven)
Jul 6, 2026
ProTip!
Advisories are also available from the
GraphQL API