GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
45
GitHub Actions
47
Go
3,309
Maven
5,000+
npm
5,000+
NuGet
876
pip
4,531
Pub
12
RubyGems
1,009
Rust
1,195
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,724 advisories
Filter by severity
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future
Moderate
CVE-2026-27195
was published
for
wasmtime
(Rust)
Feb 24, 2026
Caddy: Unicode case-folding length expansion causes incorrect split_path index in FastCGI transport
High
CVE-2026-27590
was published
for
github.com/caddyserver/caddy/v2
(Go)
Feb 24, 2026
Caddy is vulnerable to cross-origin config application via local admin API /load
Moderate
CVE-2026-27589
was published
for
github.com/caddyserver/caddy/v2
(Go)
Feb 24, 2026
Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass
High
CVE-2026-27588
was published
for
github.com/caddyserver/caddy/v2
(Go)
Feb 24, 2026
Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypass
High
CVE-2026-27587
was published
for
github.com/caddyserver/caddy/v2
(Go)
Feb 24, 2026
Caddy: mTLS client authentication silently fails open when CA certificate file is missing or malformed
High
CVE-2026-27586
was published
for
github.com/caddyserver/caddy/v2
(Go)
Feb 24, 2026
Caddy: Improper sanitization of glob characters in file matcher may lead to bypassing security protections
Moderate
CVE-2026-27585
was published
for
github.com/caddyserver/caddy/v2
(Go)
Feb 24, 2026
ActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints
Critical
CVE-2026-27584
was published
for
@actual-app/sync-server
(npm)
Feb 24, 2026
Payload: Server-Side Request Forgery (SSRF) in External File URL Uploads
Moderate
CVE-2026-27567
was published
for
payload
(npm)
Feb 24, 2026
MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
High
CVE-2026-27483
was published
for
mindsdb
(pip)
Feb 24, 2026
Pimcore vulnerable to SQL injection via unsanitized filter value in Dependency Dao RLIKE clause
Moderate
CVE-2026-27461
was published
for
pimcore/pimcore
(Composer)
Feb 24, 2026
NiceGUI vulnerable to XSS via Code Injection during client-side element function execution
Moderate
CVE-2026-27156
was published
for
nicegui
(pip)
Feb 24, 2026
FUXA has JWT Authentication Bypass via HTTP Referer header spoofing
Critical
CVE-2025-69985
was published
for
@frangoteam/fuxa
(npm)
Feb 24, 2026
nats-server websockets are vulnerable to pre-auth memory DoS
Moderate
CVE-2026-27571
was published
for
github.com/nats-io/nats-server
(Go)
Feb 24, 2026
Isso affected by Stored XSS via comment website field
Moderate
CVE-2026-27469
was published
for
isso
(pip)
Feb 24, 2026
OneUptime:: node:vm sandbox escape in probe allows any project member to achieve RCE
Critical
CVE-2026-27574
was published
for
@oneuptime/common
(npm)
Feb 24, 2026
Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
Moderate
CVE-2026-27129
was published
for
craftcms/cms
(Composer)
Feb 24, 2026
ImageMagick: Invalid MSL <map> can result in a use after free
Moderate
CVE-2026-26983
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick has a possible infinite loop in its JPEG encoder when using `jpeg:extent`
Moderate
CVE-2026-26283
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick has infinite loop when writing IPTCTEXT leads to denial of service via crafted profile
Moderate
CVE-2026-26066
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick: Integer overflow or wraparound and incorrect conversion between numeric types in the internal SVG decoder
High
CVE-2026-25989
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick: MSL image stack index may fail to refresh, leading to leaked images
Moderate
CVE-2026-25988
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick has a heap buffer over-read in its MAP image decoder
Moderate
CVE-2026-25987
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder
High
CVE-2026-25985
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick has Use After Free in MSLStartElement in "coders/msl.c"
Moderate
CVE-2026-25983
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ProTip!
Advisories are also available from the
GraphQL API