GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
942 advisories
Filter by severity
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
Critical
CVE-2026-55565
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
Critical
CVE-2026-55559
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
Critical
CVE-2026-55511
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability
Critical
CVE-2026-65905
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 26, 2026
Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability
Critical
CVE-2026-65182
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 26, 2026
Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability
Critical
CVE-2026-68525
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 26, 2026
Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
Critical
CVE-2026-78329
was published
for
org.apache.camel:camel-undertow
(Maven)
Aug 24, 2026
Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection - the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace
Critical
CVE-2026-71300
was published
for
org.apache.camel:camel-atmosphere-websocket
(Maven)
Aug 24, 2026
Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
Critical
CVE-2026-66906
was published
for
org.apache.camel:camel-azure-storage-blob
(Maven)
Aug 24, 2026
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
Critical
CVE-2026-76904
was published
for
org.geotools.jdbc:gt-jdbc-postgis
(Maven)
Aug 21, 2026
Keycloak: Unauthenticated account takeover via reset-credentials flow bypass
Critical
CVE-2026-18963
was published
for
org.keycloak:keycloak-services
(Maven)
Aug 18, 2026
Apache Ranger has a Command Injection vulnerability
Critical
CVE-2026-28672
was published
for
org.apache.ranger:ranger
(Maven)
Aug 10, 2026
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
CVE-2026-73644
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Critical
GHSA-68r5-9hpg-7qw9
was published
for
org.openidentityplatform.opendj:opendj-dsml-servlet
(Maven)
Jul 24, 2026
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
Critical
CVE-2026-62379
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Jul 24, 2026
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
Critical
CVE-2026-62263
was published
for
org.openidentityplatform.openam:openam-auth-webauthn
(Maven)
Jul 24, 2026
fastjson has a remote code execution (RCE) vulnerability
Critical
CVE-2026-16723
was published
for
com.alibaba:fastjson
(Maven)
Jul 23, 2026
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF)
Critical
CVE-2026-48205
was published
for
org.apache.camel:camel-dns
(Maven)
Jul 6, 2026
Apache Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy
Critical
CVE-2026-56140
was published
for
org.apache.camel:camel-aws2-sns
(Maven)
Jul 6, 2026
Apache Camel: KeycloakSecurityPolicy has Improper Authentication, Missing Authentication for Critical Function and Failing Open Vulnerabilities
Critical
CVE-2026-53913
was published
for
org.apache.camel:camel-keycloak
(Maven)
Jul 6, 2026
Apache Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
Critical
CVE-2026-48203
was published
for
org.apache.camel:camel-solr
(Maven)
Jul 6, 2026
Apache Camel: camel-mongodb-gridfs producer allows GridFS operation override and NoSQL operator injection via unfiltered gridfs.* HTTP headers
Critical
CVE-2026-48204
was published
for
org.apache.camel:camel-mongodb-gridfs
(Maven)
Jul 6, 2026
Apache Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers
Critical
CVE-2026-46456
was published
for
org.apache.camel:camel-aws2-sqs
(Maven)
Jul 6, 2026
Apache Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
Critical
CVE-2026-40047
was published
for
org.apache.camel:camel-docling
(Maven)
Jul 6, 2026
Apache Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted
Critical
CVE-2026-46455
was published
for
org.apache.camel:camel-keycloak
(Maven)
Jul 6, 2026
ProTip!
Advisories are also available from the
GraphQL API