GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
45
GitHub Actions
47
Go
3,309
Maven
5,000+
npm
5,000+
NuGet
876
pip
4,531
Pub
12
RubyGems
1,009
Rust
1,195
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,724 advisories
Filter by severity
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity
High
CVE-2026-27896
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Feb 26, 2026
wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup
Moderate
CVE-2026-27839
was published
for
wger
(pip)
Feb 26, 2026
wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
Low
CVE-2026-27838
was published
for
wger
(pip)
Feb 26, 2026
wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
Moderate
CVE-2026-27835
was published
for
wger
(pip)
Feb 26, 2026
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
High
CVE-2026-27903
was published
for
minimatch
(npm)
Feb 26, 2026
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
High
CVE-2026-27904
was published
for
minimatch
(npm)
Feb 26, 2026
Terraform Provider for Linode Debug Logs Vulnerable to Sensitive Information Exposure
Moderate
CVE-2026-27900
was published
for
github.com/linode/terraform-provider-linode
(Go)
Feb 26, 2026
pypdf: Manipulated FlateDecode XFA streams can exhaust RAM
Moderate
CVE-2026-27888
was published
for
pypdf
(pip)
Feb 26, 2026
dottie is vulnerable to Prototype Pollution bypass via non-first path segments in set() and transform()
Moderate
CVE-2026-27837
was published
for
dottie
(npm)
Feb 26, 2026
Fleet: Sensitive Google Calendar credentials disclosed to low-privileged users
High
CVE-2026-27465
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 26, 2026
Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
Moderate
CVE-2026-27457
was published
for
weblate
(pip)
Feb 26, 2026
Fleet: Authorization Bypass in certificate template batch deletion for team administrators
Moderate
CVE-2026-25963
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 26, 2026
Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint
Moderate
CVE-2026-24004
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 26, 2026
Fleet: Device lock PIN can be predicted if lock time is known
Moderate
CVE-2026-23999
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 26, 2026
n8n: Webhook Forgery on Github Webhook Trigger
Moderate
GHSA-mqpr-49jj-32rc
was published
for
n8n
(npm)
Feb 26, 2026
n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes
Moderate
GHSA-f3f2-mcxc-pwjx
was published
for
n8n
(npm)
Feb 26, 2026
Vikunja has Path Traversal in CLI Restore
High
CVE-2026-27819
was published
for
code.vikunja.io/api
(Go)
Feb 26, 2026
TerriaJS-Server has a domain validation bypass vulnerability in its proxy allowlist
High
CVE-2026-27818
was published
for
terriajs-server
(npm)
Feb 26, 2026
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API
Moderate
CVE-2026-27808
was published
for
github.com/axllent/mailpit
(Go)
Feb 26, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Moderate
CVE-2026-27735
was published
for
mcp-server-git
(pip)
Feb 26, 2026
Storybook Dev Server is Vulnerable to WebSocket Hijacking
High
CVE-2026-27148
was published
for
storybook
(npm)
Feb 26, 2026
Fleet has an SQL Injection vulnerability via backtick escape in ORDER BY parameter
Moderate
CVE-2026-26186
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 26, 2026
Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter
Critical
CVE-2026-27804
was published
for
parse-server
(npm)
Feb 25, 2026
Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover
Critical
CVE-2026-27822
was published
for
rustfs
(Rust)
Feb 25, 2026
ProTip!
Advisories are also available from the
GraphQL API