GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
117
GitHub Actions
55
Go
4,837
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,577
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
35,910 advisories
Filter by severity
Snipe-IT: 2FA bypass via the API token flow
High
CVE-2026-63493
was published
for
snipe/snipe-it
(Composer)
Sep 24, 2026
podman quadlet install --replace does not fully replace the old file
Moderate
CVE-2026-19730
was published
for
github.com/containers/podman/v5
(Go)
Sep 24, 2026
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files
Moderate
CVE-2026-92164
was published
for
streamlink
(pip)
Sep 24, 2026
SunEditor: Critical XSS vulnerability - sanitizer bypass
Critical
CVE-2026-59167
was published
for
suneditor
(npm)
Sep 24, 2026
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration
Moderate
CVE-2026-62998
was published
for
redaxo/source
(Composer)
Sep 24, 2026
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
High
CVE-2026-56669
was published
for
elysia
(npm)
Sep 23, 2026
ReactPress has SQL injection via dynamic column names in TypeORM query builders
High
CVE-2026-61685
was published
for
@fecommunity/reactpress
(npm)
Sep 23, 2026
plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length
Moderate
GHSA-8pcw-h6w9-h46g
was published
for
plone.app.contenttypes
(pip)
Sep 23, 2026
plone.app.dexterity has a Denial of Service due to excessive title or description length
Moderate
CVE-2026-57576
was published
for
plone.app.dexterity
(pip)
Sep 23, 2026
OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget
High
CVE-2026-77394
was published
for
@openc3/vue-common
(npm)
Sep 23, 2026
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS
High
CVE-2026-82407
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery
High
CVE-2026-82409
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace
High
CVE-2026-82406
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Formie: Missing authorization on sent notification resend modal exposes submission PII
High
CVE-2026-76089
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Jawn: Quadratic parsing effort in AsyncParser
High
CVE-2026-61814
was published
for
org.typelevel:jawn-parser_2.12
(Maven)
Sep 23, 2026
Jawn: Uncontrolled nesting depth in JSON parser
High
CVE-2026-59990
was published
for
org.typelevel:jawn-parser_2.12
(Maven)
Sep 23, 2026
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller
High
CVE-2026-82405
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)
High
CVE-2026-86065
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: /log controls global node logging
High
CVE-2026-86064
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
Moderate
CVE-2026-93421
was published
for
mesop
(pip)
Sep 23, 2026
OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites)
Critical
CVE-2026-77602
was published
for
openc3
(RubyGems)
Sep 23, 2026
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting
High
CVE-2026-77601
was published
for
openc3
(RubyGems)
Sep 23, 2026
Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup() crashes any protobuf-decoding service
High
CVE-2026-61695
was published
for
github.com/square/wire
(Swift)
Sep 23, 2026
Formie: Unauthenticated users can overwrite incomplete submissions via submit action
High
CVE-2026-76087
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials
High
CVE-2026-76086
was published
for
verbb/formie
(Composer)
Sep 23, 2026
ProTip!
Advisories are also available from the
GraphQL API