GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
45
GitHub Actions
47
Go
3,308
Maven
5,000+
npm
5,000+
NuGet
876
pip
4,530
Pub
12
RubyGems
1,009
Rust
1,195
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,718 advisories
Filter by severity
osctrl is Vulnerable to OS Command Injection via Environment Configuration
High
CVE-2026-28279
was published
for
github.com/jmpsec/osctrl
(Go)
Feb 28, 2026
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
Low
GHSA-fpg4-jhqr-589c
was published
for
@sveltejs/kit
(npm)
Feb 28, 2026
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
High
GHSA-72hv-8253-57qq
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Feb 28, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse
Critical
CVE-2026-28268
was published
for
code.vikunja.io/api
(Go)
Feb 28, 2026
Junrar has an arbitrary file write due to backslash Path Traversal bypass in LocalFolderExtractor on Linux/Unix
Moderate
CVE-2026-28208
was published
for
com.github.junrar:junrar
(Maven)
Feb 27, 2026
OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata
Moderate
GHSA-7jx5-9fjg-hp4m
was published
for
openclaw
(npm)
Feb 27, 2026
OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth)
Moderate
CVE-2026-4039
was published
for
openclaw
(npm)
Feb 27, 2026
Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass
High
CVE-2026-27939
was published
for
statamic/cms
(Composer)
Feb 27, 2026
ZITADEL has potential SSRF via Actions
Low
CVE-2026-27945
was published
for
github.com/zitadel/zitadel/v2
(Go)
Feb 27, 2026
ZITADEL Users Can Self-Verify Email/Phone via UpdateHumanUser API
High
CVE-2026-27946
was published
for
github.com/zitadel/zitadel
(Go)
Feb 27, 2026
ZITADEL's truncated opaque tokens are still valid
Moderate
CVE-2026-27840
was published
for
github.com/zitadel/zitadel
(Go)
Feb 27, 2026
phpMyFAQ Allows Unauthenticated Account Creation via WebAuthn Prepare Endpoint
High
CVE-2026-27836
was published
for
thorsten/phpmyfaq
(Composer)
Feb 27, 2026
Beszel: Docker API has a Path Traversal Vulnerability via Unsanitized Container ID
Moderate
CVE-2026-27734
was published
for
github.com/henrygd/beszel
(Go)
Feb 27, 2026
@actual-app/sync-server: Missing authorization in sync endpoints allows cross-user budget file access in multi-user mode
Moderate
CVE-2026-27638
was published
for
@actual-app/sync-server
(npm)
Feb 27, 2026
Umbraco.Engage.Forms Allows Unauthorized Access to Multiple API Endpoints
High
CVE-2026-27449
was published
for
Umbraco.Engage.Forms
(NuGet)
Feb 27, 2026
Angular i18n vulnerable to Cross-Site Scripting
High
CVE-2026-27970
was published
for
@angular/core
(npm)
Feb 27, 2026
Duplicate Advisory: Nest has a Fastify URL Encoding Middleware Bypass
High
GHSA-7q64-3rg2-h9pf
was published
for
@nestjs/platform-fastify
(npm)
Feb 27, 2026
•
withdrawn
CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage
High
CVE-2026-26862
was published
for
clevertap-web-sdk
(npm)
Feb 27, 2026
CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function
High
CVE-2026-26861
was published
for
clevertap-web-sdk
(npm)
Feb 27, 2026
Vitess users with backup storage access can write to arbitrary file paths on restore
Critical
CVE-2026-27969
was published
for
vitess.io/vitess
(Go)
Feb 27, 2026
AWS CLI: cli_history database does not restrict file permissions on Unix systems
Moderate
GHSA-747p-wmpv-9c78
was published
for
awscli
(pip)
Feb 27, 2026
Langflow has Remote Code Execution in CSV Agent
Critical
CVE-2026-27966
was published
for
langflow
(pip)
Feb 27, 2026
uv has ZIP payload obfuscation through parsing differentials
Moderate
CVE-2025-13327
was published
for
uv
(Rust)
Feb 27, 2026
rubyipmi is vulnerable to OS Command Injection through malicious usernames
High
CVE-2026-0980
was published
for
rubyipmi
(RubyGems)
Feb 27, 2026
Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes
Moderate
CVE-2026-0871
was published
for
org.keycloak:keycloak-server-spi-private
(Maven)
Feb 27, 2026
ProTip!
Advisories are also available from the
GraphQL API