GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
271 advisories
Filter by severity
Duplicate Advisory: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol
High
GHSA-79ph-w9m5-4v5m
was published
for
nltk
(pip)
Aug 22, 2026
•
withdrawn
Gitea draft releases and attachments are exposed without write permission
High
CVE-2026-27660
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea forwarded-proto validation allows canonical URL spoofing
High
CVE-2026-27779
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea organization permission APIs expose hidden membership and private organization data
High
CVE-2026-25712
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea pull request branch permission checks allow unauthorized updates and rebases
High
CVE-2026-24690
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Incus has a project restriction bypass in instance copy across projects
High
CVE-2026-55622
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Aug 28, 2026
Incus has a project restriction bypass for custom volume copy across projects
High
CVE-2026-55621
was published
for
github.com/lxc/incus
(Go)
Aug 28, 2026
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
High
CVE-2026-53832
was published
for
openclaw
(npm)
Jul 2, 2026
Filestash allows attackers to escalate privileges via sending a crafted request
High
CVE-2026-50891
was published
for
github.com/mickael-kerjean/filestash
(Go)
Jun 15, 2026
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components
High
CVE-2026-50884
was published
for
github.com/statping-ng/statping-ng
(Go)
Jun 15, 2026
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
High
CVE-2026-53831
was published
for
openclaw
(npm)
Jul 2, 2026
Spring for GraphQL: Annotation Detection Vulnerability
High
CVE-2026-41856
was published
for
org.springframework.graphql:spring-graphql
(Maven)
Jun 11, 2026
MLflow: trace API endpoints lack proper authorization validators
High
CVE-2026-8147
was published
for
mlflow
(pip)
Jul 2, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
High
CVE-2026-54526
was published
for
github.com/argoproj/argo-workflows
(Go)
Aug 13, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
High
CVE-2026-52810
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Spring Data REST has Improper Access Control in its JSON Patch Implementation
High
CVE-2026-41728
was published
for
org.springframework.data:spring-data-rest-core
(Maven)
Jun 10, 2026
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
High
CVE-2026-70476
was published
for
flowise
(npm)
Aug 4, 2026
MCP Ruby SDK: Ruby SSE Session Poisoning
High
CVE-2026-67431
was published
for
mcp
(RubyGems)
Jul 30, 2026
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
High
CVE-2026-41006
was published
for
org.springframework.hateoas:spring-hateoas
(Maven)
Jun 9, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
High
CVE-2026-58422
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
High
CVE-2026-24451
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Repository Visibility Manipulation via Git Push Options
High
CVE-2026-58437
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
High
CVE-2026-58421
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
High
CVE-2026-50132
was published
for
@budibase/server
(npm)
Jun 22, 2026
ProTip!
Advisories are also available from the
GraphQL API