GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,578
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,473 advisories
Filter by severity
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
High
CVE-2026-55477
was published
for
github.com/mhsanaei/3x-ui/v2
(Go)
Aug 24, 2026
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
Moderate
GHSA-rgqc-3x5p-6gwg
was published
for
postgres-protocol
(Rust)
Aug 24, 2026
Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
High
CVE-2026-63421
was published
for
@keystone-6/core
(npm)
Aug 21, 2026
Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)
High
CVE-2026-54182
was published
for
backpack/crud
(Composer)
Aug 20, 2026
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
Moderate
GHSA-5p3m-vhh6-9236
was published
for
stigmem-node
(pip)
Aug 20, 2026
BuildKit: Custom frontend could bypass Seccomp/AppArmor
Moderate
CVE-2026-61711
was published
for
github.com/moby/buildkit
(Go)
Aug 19, 2026
Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields
Moderate
CVE-2026-54543
was published
for
froxlor/froxlor
(Composer)
Aug 18, 2026
jmespath.php has CompilerRuntime code injection via unescaped function names
Critical
CVE-2026-54133
was published
for
mtdowling/jmespath.php
(Composer)
Aug 18, 2026
MeshCentral has unsanitized data fields
High
GHSA-c7hr-448w-65px
was published
for
meshcentral
(npm)
Aug 18, 2026
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
Low
CVE-2026-61634
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
RabbitMQ Java client malformed body frame triggers raw command assembler exception
Moderate
CVE-2026-63335
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
package pkcs12: Authentication bypass in Decode functions
Moderate
GHSA-mpwr-8vm7-h73f
was published
for
software.sslmate.com/src/go-pkcs12
(Go)
Aug 17, 2026
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
Moderate
CVE-2026-45099
was published
for
github.com/gruntwork-io/terragrunt
(Go)
Aug 17, 2026
Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name
High
CVE-2026-55072
was published
for
pimcore/pimcore
(Composer)
Aug 13, 2026
phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration
Moderate
CVE-2026-47132
was published
for
thorsten/phpmyfaq
(Composer)
Aug 12, 2026
Nuxt: Unauthorized Component Instantiation via Server Island Props
Moderate
CVE-2026-71318
was published
for
nuxt
(npm)
Aug 5, 2026
Electron: window.open features string controls some window options considered privileged
Moderate
CVE-2026-70607
was published
for
electron
(npm)
Aug 5, 2026
Electron: shell.openPath path validation bypass via embedded null byte
Moderate
CVE-2026-70603
was published
for
electron
(npm)
Aug 5, 2026
Ghost: Archived Offers can be Redeemed
Moderate
CVE-2026-70589
was published
for
ghost
(npm)
Aug 4, 2026
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
Moderate
CVE-2026-59881
was published
for
aiohttp
(pip)
Aug 3, 2026
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
High
CVE-2026-69192
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-69198
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-54272
was published
for
ip-address
(npm)
Aug 3, 2026
Socket.IO: Zero-attachment Memory Exhaustion
High
CVE-2026-69185
was published
for
socket.io-parser
(npm)
Aug 3, 2026
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Moderate
CVE-2026-54909
was published
for
github.com/pion/stun
(Go)
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API