GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,091 advisories
Filter by severity
Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a...
High
Unreviewed
CVE-2026-85053
was published
Sep 3, 2026
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
Critical
CVE-2026-73843
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view...
Moderate
Unreviewed
CVE-2026-82652
was published
Aug 30, 2026
SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the...
Moderate
Unreviewed
CVE-2026-82650
was published
Aug 30, 2026
Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79068
was published
Aug 25, 2026
Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote...
Low
Unreviewed
CVE-2026-79031
was published
Aug 25, 2026
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between...
Moderate
Unreviewed
CVE-2026-59308
was published
Aug 21, 2026
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
Duplicate Advisory: Craft CMS: Authenticated leak of secret environment variables
High
GHSA-cc2g-26rw-g997
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
n8n's JavaScript task runner shared a single module cache across all users' Code-node executions....
Moderate
Unreviewed
CVE-2026-72764
was published
Aug 11, 2026
Craft CMS: Authenticated leak of secret environment variables
Moderate
CVE-2026-72782
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
Moderate
CVE-2026-70606
was published
for
electron
(npm)
Aug 5, 2026
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
High
CVE-2026-67427
was published
for
flyto-core
(pip)
Jul 30, 2026
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
High
CVE-2026-54727
was published
for
proot-distro
(pip)
Jul 29, 2026
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
High
CVE-2026-54504
was published
for
@andrea9293/mcp-documentation-server
(npm)
Jul 15, 2026
ViewComponent: Reused Component Instances Retain Stale Render Context
Moderate
CVE-2026-54497
was published
for
view_component
(RubyGems)
Jul 15, 2026
open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters
Moderate
CVE-2026-54495
was published
for
github.com/open-feature/open-feature-operator
(Go)
Jul 15, 2026
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2...
High
Unreviewed
CVE-2026-59835
was published
Jul 14, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
Moderate
CVE-2026-50202
was published
for
Steeltoe.Security.Authentication.CloudFoundryBase
(NuGet)
Jul 2, 2026
OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
Moderate
GHSA-6c4r-g249-wv3c
was published
for
openclaw
(npm)
Jul 2, 2026
PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger...
High
Unreviewed
CVE-2026-56077
was published
Jun 19, 2026
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
High
CVE-2026-57144
was published
for
praisonai
(pip)
Jun 18, 2026
OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session...
Low
Unreviewed
CVE-2026-53826
was published
Jun 13, 2026
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
High
CVE-2026-54096
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
Moderate
CVE-2026-48096
was published
for
github.com/openfga/openfga
(Go)
Jun 11, 2026
ProTip!
Advisories are also available from the
GraphQL API