GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,359
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,554
Pub
12
RubyGems
1,013
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,996 advisories
Filter by severity
markdown-it is has a Regular Expression Denial of Service (ReDoS)
Moderate
CVE-2026-2327
was published
for
markdown-it
(npm)
Feb 12, 2026
next-mdx-remote affected by arbitrary code execution in React server-side rendering of untrusted MDX content
High
CVE-2026-0969
was published
for
next-mdx-remote
(npm)
Feb 12, 2026
Duplicate Advisory: Keras vulnerable to arbitrary file read in the model loading mechanism (HDF5 integration)
High
GHSA-gfmx-qqqh-f38q
was published
for
keras
(pip)
Feb 12, 2026
•
withdrawn
DiskCache has unsafe pickle deserialization
Moderate
CVE-2025-69872
was published
for
diskcache
(pip)
Feb 11, 2026
ajv has ReDoS when using `$data` option
Moderate
CVE-2025-69873
was published
for
ajv
(npm)
Feb 11, 2026
Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
Critical
CVE-2026-26190
was published
for
github.com/milvus-io/milvus
(Go)
Feb 11, 2026
Vikunja Vulnerable to XSS Via Task Preview
High
CVE-2026-25935
was published
for
code.vikunja.io/api
(Go)
Feb 11, 2026
nanotar is vulnerable to path traversal in parseTar() and parseTarGzip()
Moderate
CVE-2025-69874
was published
for
nanotar
(npm)
Feb 11, 2026
Statamic CMS vulnerable to privilege escalation via stored cross-site scripting
High
CVE-2026-25759
was published
for
statamic/cms
(Composer)
Feb 11, 2026
Statamic CMS's missing authorization allows access to assets
Moderate
CVE-2026-25633
was published
for
statamic/cms
(Composer)
Feb 11, 2026
Kimai 2 vulnerable to persistent cross-site scripting in the timesheet descriptions
Moderate
CVE-2019-25317
was published
for
kimai/kimai
(Composer)
Feb 11, 2026
Phraseanet vulnerable to stored cross-site scripting through crafted file names
Moderate
CVE-2018-25157
was published
for
phraseanet/phraseanet
(Composer)
Feb 11, 2026
set-in Affected by Prototype Pollution
Critical
CVE-2026-26021
was published
for
set-in
(npm)
Feb 11, 2026
@langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation
Moderate
CVE-2026-26019
was published
for
@langchain/community
(npm)
Feb 11, 2026
Pion DTLS's usage of random nonce generation with AES GCM ciphers risks leaking the authentication key
Moderate
CVE-2026-26014
was published
for
github.com/pion/dtls
(Go)
Feb 11, 2026
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
Low
CVE-2026-26013
was published
for
langchain-core
(pip)
Feb 11, 2026
Leaky JWTs in OpenMetadata exposing highly-privileged bot users
High
CVE-2026-26010
was published
for
org.open-metadata:openmetadata-sdk
(Maven)
Feb 11, 2026
Pillow affected by out-of-bounds write when loading PSD images
High
CVE-2026-25990
was published
for
pillow
(pip)
Feb 11, 2026
Microsoft Security Advisory CVE-2026-21218 | .NET Security Feature Bypass Vulnerability
High
CVE-2026-21218
was published
for
System.Security.Cryptography.Cose
(NuGet)
Feb 10, 2026
cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
High
CVE-2026-26007
was published
for
cryptography
(pip)
Feb 10, 2026
Azure AI Language Authoring Elevation of Privilege Vulnerability can Lead to RCE
Critical
CVE-2026-21531
was published
for
azure-ai-language-conversations-authoring
(pip)
Feb 10, 2026
CASL Ability is Vulnerable to Prototype Pollution
Critical
CVE-2026-1774
was published
for
@casl/ability
(npm)
Feb 10, 2026
cap-go/capacitor-native-biometric Authentication Bypass
Moderate
GHSA-vx5f-vmr6-32wf
was published
for
@capgo/capacitor-native-biometric
(npm)
Feb 10, 2026
Emmett-Core: Unhandled CookieError Exception Causing Denial of Service
High
CVE-2026-25577
was published
for
emmett-core
(pip)
Feb 10, 2026
Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability
Low
CVE-2026-23901
was published
for
org.apache.shiro:shiro-core
(Maven)
Feb 10, 2026
ProTip!
Advisories are also available from the
GraphQL API