GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses
Moderate
GHSA-7jmw-8259-q9jx
was published
for
github.com/traefik/traefik
(Go)
Jun 11, 2024
zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
High
CVE-2025-29787
was published
for
zip
(Rust)
Mar 17, 2025
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP
High
CVE-2026-24895
was published
for
github.com/dunglas/frankenphp
(Go)
Feb 12, 2026
OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths
Moderate
CVE-2026-32033
was published
for
openclaw
(npm)
Mar 3, 2026
Rack:: Static header_rules bypass via URL-encoded paths
Moderate
CVE-2026-34786
was published
for
rack
(RubyGems)
Apr 2, 2026
Vite: `server.fs.deny` bypassed with queries
High
CVE-2026-39364
was published
for
vite
(npm)
Apr 6, 2026
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
Moderate
CVE-2026-39409
was published
for
hono
(npm)
Apr 8, 2026
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
High
CVE-2026-45022
was published
for
github.com/go-git/go-git/v5
(Go)
May 11, 2026
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
High
CVE-2026-42462
was published
for
@fedify/fedify
(npm)
May 26, 2026
Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass
Critical
CVE-2026-44180
was published
for
jupyter_enterprise_gateway
(pip)
Jun 3, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Moderate
GHSA-89vp-jrxv-24w8
was published
for
jupyterlab
(pip)
Jul 22, 2026
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Critical
GHSA-7rqj-j65f-68wh
was published
for
@auth/core
(npm)
Jul 23, 2026
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
Moderate
CVE-2026-7120
was published
for
@fastify/static
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API