GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
48
Go
3,399
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,618
Pub
13
RubyGems
1,026
Rust
1,205
Swift
52
Unreviewed advisories
All unreviewed
5,000+
28,315 advisories
Filter by severity
protobuf affected by a JSON recursion depth bypass
High
CVE-2026-0994
was published
for
protobuf
(pip)
Jan 23, 2026
Moodle affected by a code injection vulnerability
High
CVE-2025-67847
was published
for
moodle/moodle
(Composer)
Jan 23, 2026
Langflow affected by Remote Code Execution via validate_code() exec()
High
CVE-2026-0770
was published
for
langflow
(pip)
Jan 23, 2026
Duplicate Advisory: npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
High
CVE-2026-0775
was published
for
npm
(npm)
Jan 23, 2026
•
withdrawn
Gitea does not properly validate repository ownership when linking attachments to releases
Moderate
CVE-2026-20912
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Moderate
CVE-2026-20904
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Moderate
CVE-2026-20750
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Moderate
CVE-2026-20897
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea may send release notification emails for private repositories to users whose access has been revoked
Low
CVE-2026-0798
was published
for
code.gitea.io/gitea
(Go)
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
CVE-2026-20800
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
CVE-2026-20883
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Moderate
CVE-2026-20888
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea has improper access control for uploaded attachments
Low
CVE-2026-20736
was published
for
code.gitea.io/gitea
(Go)
Jan 23, 2026
Container and Containerization archive extraction does not guard against escapes from extraction base directory.
Low
CVE-2026-20613
was published
for
github.com/apple/container
(Swift)
Jan 22, 2026
Freeform Craft Plugin CP UI (builder/integrations) has Stored Cross-Site Scripting (XSS) issue
Low
CVE-2026-26188
was published
for
solspace/craft-freeform
(Composer)
Jan 22, 2026
Spring Security has a broken timing attack mitigation implemented in DaoAuthenticationProvide
Moderate
CVE-2025-22234
was published
for
org.springframework.security:spring-security-core
(Maven)
Jan 22, 2026
sigstore legacy TUF client allows for arbitrary file writes with target cache path traversal
Moderate
CVE-2026-24137
was published
for
github.com/sigstore/sigstore
(Go)
Jan 22, 2026
Incus container image templating arbitrary host file read and write
High
CVE-2026-23954
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
Jan 22, 2026
Incus container environment configuration newline injection
High
CVE-2026-23953
was published
for
github.com/lxc/incus/v6
(Go)
Jan 22, 2026
Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URL
Moderate
CVE-2026-24117
was published
for
github.com/sigstore/rekor
(Go)
Jan 22, 2026
Rekor's COSE v0.0.1 entry type nil pointer dereference in Canonicalize via empty Message
Moderate
CVE-2026-23831
was published
for
github.com/sigstore/rekor
(Go)
Jan 22, 2026
Sentencepiece has a a heap overflow issue
High
CVE-2026-1260
was published
for
sentencepiece
(pip)
Jan 22, 2026
orjson does not limit recursion for deeply nested JSON documents
High
CVE-2025-67221
was published
for
orjson
(pip)
Jan 22, 2026
Beam Exposes sensitive information via joinCleanPath function
Moderate
CVE-2025-69820
was published
for
github.com/beam-cloud/beta9
(Go)
Jan 22, 2026
Orval Mock Generation Code Injection via const
High
CVE-2026-24132
was published
for
@orval/mock
(npm)
Jan 22, 2026
ProTip!
Advisories are also available from the
GraphQL API