GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,513
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34,430 advisories
Filter by severity
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Moderate
CVE-2026-53708
was published
for
mcp-contextforge-gateway
(pip)
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
Moderate
GHSA-8rw6-p7m8-63jp
was published
for
surrealdb
(Rust)
Aug 14, 2026
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
High
CVE-2026-55153
was published
for
com.mchange:mchange-commons-java
(Maven)
Aug 14, 2026
OpenAM Insecure SSO Cookie Initialization
High
CVE-2026-53660
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Aug 14, 2026
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Moderate
CVE-2026-53658
was published
for
github.com/hyperledger/fabric-ca
(Go)
Aug 14, 2026
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
Grav: Unauthenticated denial of service via unbounded image derivative dimensions
High
CVE-2026-53653
was published
for
getgrav/grav
(Composer)
Aug 14, 2026
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
High
CVE-2026-35219
was published
for
@budibase/server
(npm)
Aug 14, 2026
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
High
CVE-2026-35511
was published
for
github.com/authorizerdev/authorizer
(Go)
Aug 14, 2026
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
High
CVE-2026-73654
was published
for
@trigger.dev/core
(npm)
Aug 13, 2026
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
High
CVE-2026-12243
was published
for
nltk
(pip)
Aug 13, 2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Moderate
CVE-2026-73559
was published
for
vllm
(pip)
Aug 13, 2026
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
High
GHSA-rm43-82j9-r4mj
was published
for
atomic-agents-stack
(pip)
Aug 13, 2026
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Moderate
CVE-2026-54249
was published
for
pydantic-ai
(pip)
Aug 13, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
High
CVE-2026-54526
was published
for
github.com/argoproj/argo-workflows
(Go)
Aug 13, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors
Moderate
CVE-2026-55102
was published
for
hashi-vault-js
(npm)
Aug 13, 2026
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
Moderate
CVE-2026-55088
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
Moderate
CVE-2026-55086
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
Moderate
CVE-2026-55087
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name
High
CVE-2026-55072
was published
for
pimcore/pimcore
(Composer)
Aug 13, 2026
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
High
CVE-2026-55074
was published
for
ansible-jailexec
(pip)
Aug 12, 2026
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
High
GHSA-pfvm-w89x-94jw
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
High
GHSA-jwjp-4649-v8jp
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
High
CVE-2026-55071
was published
for
stata-mcp
(pip)
Aug 12, 2026
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
High
CVE-2026-54917
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 12, 2026
ProTip!
Advisories are also available from the
GraphQL API