GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,905 advisories
Filter by severity
RediSearch Query Injection in @langchain/langgraph-checkpoint-redis
Moderate
CVE-2026-27022
was published
for
@langchain/langgraph-checkpoint-redis
(npm)
Feb 18, 2026
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
High
CVE-2026-26996
was published
for
minimatch
(npm)
Feb 18, 2026
filippo.io/edwards25519 MultiScalarMult produces invalid results or undefined behavior if receiver is not the identity
Low
CVE-2026-26958
was published
for
filippo.io/edwards25519
(Go)
Feb 18, 2026
Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation
High
CVE-2026-26318
was published
for
systeminformation
(npm)
Feb 18, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake
Moderate
CVE-2026-26315
was published
for
github.com/ethereum/go-ethereum
(Go)
Feb 18, 2026
Go Ethereum affected by DoS via malicious p2p message
High
CVE-2026-26314
was published
for
github.com/ethereum/go-ethereum
(Go)
Feb 18, 2026
Go Ethereum affected by DoS via malicious p2p message
Moderate
CVE-2026-26313
was published
for
github.com/ethereum/go-ethereum
(Go)
Feb 18, 2026
uTLS has a fingerprint vulnerability from missing padding extension for Chrome 120
Low
CVE-2026-26995
was published
for
github.com/refraction-networking/utls
(Go)
Feb 18, 2026
uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots
Low
CVE-2026-27017
was published
for
github.com/refraction-networking/utls
(Go)
Feb 18, 2026
LibreNMS has a Time-Based Blind SQL Injection in address-search.inc.php
High
CVE-2026-26990
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS has a Stored XSS in Alert Rule
Moderate
CVE-2026-26989
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS: SQL Injection in ajax_table.php spreads through a covert data stream.
High
CVE-2026-26988
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS has a Stored XSS in Custom OID - unit parameter missing strip_tags()
Moderate
CVE-2026-27016
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS /port-groups name Stored Cross-Site Scripting
Moderate
CVE-2026-26992
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS /device-groups name Stored Cross-Site Scripting
Moderate
CVE-2026-26991
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS affected by reflected xss via email field
Moderate
CVE-2026-26987
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
Nokogiri does not check the return value from xmlC14NExecute
Moderate
GHSA-wx95-c6cv-8532
was published
for
nokogiri
(RubyGems)
Feb 18, 2026
Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path
High
CVE-2026-26280
was published
for
systeminformation
(npm)
Feb 18, 2026
Ghost has a SQL injection in Content API
Critical
CVE-2026-26980
was published
for
ghost
(npm)
Feb 18, 2026
Improper Control of Generation of Code ('Code Injection') in @tygo-van-den-hurk/slyde
High
CVE-2026-26974
was published
for
@tygo-van-den-hurk/slyde
(npm)
Feb 18, 2026
mingSoft MCMS does not properly restrict file uploads
Low
CVE-2026-2666
was published
for
net.mingsoft:ms-mcms
(Maven)
Feb 18, 2026
OpenStack Nova calls qemu-img without format restrictions for resize
High
CVE-2026-24708
was published
for
Nova
(pip)
Feb 18, 2026
Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
High
GHSA-97f8-7cmv-76j2
was published
for
picklescan
(pip)
Feb 18, 2026
OpenClaw has an authentication bypass in sandbox browser bridge server
High
CVE-2026-28468
was published
for
openclaw
(npm)
Feb 18, 2026
ProTip!
Advisories are also available from the
GraphQL API