GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
48
Go
3,399
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,618
Pub
13
RubyGems
1,026
Rust
1,205
Swift
52
Unreviewed advisories
All unreviewed
5,000+
28,315 advisories
Filter by severity
Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization
Moderate
CVE-2026-23946
was published
for
tendenci
(pip)
Jan 21, 2026
@envelop/graphql-modules has a Race Condition vulnerability
High
GHSA-h3hw-29fv-2x75
was published
for
@envelop/graphql-modules
(npm)
Jan 21, 2026
go-tuf improperly validates the configured threshold for delegations
Moderate
CVE-2026-23992
was published
for
github.com/theupdateframework/go-tuf/v2
(Go)
Jan 21, 2026
go-tuf affected by client DoS via malformed server response
Moderate
CVE-2026-23991
was published
for
github.com/theupdateframework/go-tuf/v2
(Go)
Jan 21, 2026
sm-crypto Affected by Signature Forgery in SM2-DSA
High
CVE-2026-23965
was published
for
sm-crypto
(npm)
Jan 21, 2026
sm-crypto Affected by Signature Malleability in SM2-DSA
High
CVE-2026-23967
was published
for
sm-crypto
(npm)
Jan 21, 2026
sm-crypto Affected by Private Key Recovery in SM2-PKE
Critical
CVE-2026-23966
was published
for
sm-crypto
(npm)
Jan 21, 2026
CoreShop Vulnerable to SQL Injection via Admin customer-company-modifier
Moderate
CVE-2026-23959
was published
for
coreshop/core-shop
(Composer)
Jan 21, 2026
vLLM affected by RCE via auto_map dynamic module loading during model initialization
High
CVE-2026-22807
was published
for
vllm
(pip)
Jan 21, 2026
mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport
Moderate
CVE-2026-0895
was published
for
cpsit/typo3-mailqueue
(Composer)
Jan 21, 2026
seroval Affected by Remote Code Execution via JSON Deserialization
High
CVE-2026-23737
was published
for
seroval
(npm)
Jan 21, 2026
seroval Affected by Prototype Pollution via JSON Deserialization
High
CVE-2026-23736
was published
for
seroval
(npm)
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
Critical
CVE-2026-23524
was published
for
laravel/reverb
(Composer)
Jan 21, 2026
Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
High
CVE-2026-22022
was published
for
org.apache.solr:solr-core
(Maven)
Jan 21, 2026
Apache Solr: Insufficient file-access checking in standalone core-creation requests
High
CVE-2026-22444
was published
for
org.apache.solr:solr-core
(Maven)
Jan 21, 2026
Keycloak Admin REST API exposes backend schema and rules
Low
CVE-2025-14083
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 21, 2026
Keycloak services allows the issuance of access and refresh tokens for disabled users
Moderate
CVE-2025-14559
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 21, 2026
Keycloak does not validate and update refresh token usage atomically
Low
CVE-2026-1035
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 21, 2026
ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load
Moderate
CVE-2026-23952
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jan 21, 2026
ImageMagick has a Memory Leak in LoadOpenCLDeviceBenchmark() when parsing malformed XML
Moderate
GHSA-qp59-x883-77qv
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jan 21, 2026
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
High
CVE-2026-23950
was published
for
tar
(npm)
Jan 21, 2026
ImageMagick MSL: Stack overflow via infinite recursion in ProcessMSLScript
Moderate
CVE-2026-23874
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jan 21, 2026
Swift W3C TraceContext vulnerable to a malformed HTTP header causing a crash
Moderate
CVE-2026-23886
was published
for
github.com/swift-otel/swift-otel
(Swift)
Jan 21, 2026
AlchemyCMS: Authenticated Remote Code Execution (RCE) via eval injection in ResourcesHelper
Moderate
CVE-2026-23885
was published
for
alchemy_cms
(RubyGems)
Jan 21, 2026
ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
Moderate
CVE-2026-23833
was published
for
esphome
(pip)
Jan 21, 2026
ProTip!
Advisories are also available from the
GraphQL API