GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,407 advisories
Filter by severity
Duplicate Advisory: Wrangler affected by OS Command Injection in `wrangler pages deploy`
High
GHSA-8h3q-9fpp-c883
was published
for
wrangler
(npm)
Jan 21, 2026
•
withdrawn
binary-parser library has a code injection vulnerability
Moderate
CVE-2026-1245
was published
for
binary-parser
(npm)
Jan 20, 2026
Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment
Critical
CVE-2026-23518
was published
for
github.com/fleetdm/fleet
(Go)
Jan 20, 2026
Fleet has an Access Control vulnerability in debug/pprof endpoints
High
CVE-2026-23517
was published
for
github.com/fleetdm/fleet
(Go)
Jan 20, 2026
Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability
Moderate
CVE-2026-22808
was published
for
github.com/fleetdm/fleet
(Go)
Jan 20, 2026
Turbo Frame responses can restore stale session cookies
Low
CVE-2025-66803
was published
for
@hotwired/turbo
(npm)
Jan 20, 2026
ChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion
High
CVE-2026-23842
was published
for
chatterbot
(pip)
Jan 20, 2026
XDocReport affected by an XML External Entity (XXE) vulnerability
Critical
CVE-2025-65482
was published
for
fr.opensagres.xdocreport:fr.opensagres.xdocreport.document
(Maven)
Jan 20, 2026
XDocReport affected by a Server-Side Template Injection (SSTI) vulnerability
Critical
CVE-2025-64087
was published
for
fr.opensagres.xdocreport:fr.opensagres.xdocreport.template.freemarker
(Maven)
Jan 20, 2026
Mailpit has an SMTP Header Injection via Regex Bypass
Moderate
CVE-2026-23829
was published
for
github.com/axllent/mailpit
(Go)
Jan 20, 2026
Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE)
Critical
CVE-2026-23733
was published
for
@lobehub/chat
(npm)
Jan 20, 2026
ImageMagick releases an invalid pointer in BilateralBlur when memory allocation fails
Moderate
CVE-2026-22770
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jan 20, 2026
esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages
High
CVE-2026-23644
was published
for
github.com/esm-dev/esm.sh
(Go)
Jan 20, 2026
Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion
Low
CVE-2026-23522
was published
for
@lobehub/chat
(npm)
Jan 20, 2026
Kimai has an Authenticated Server-Side Template Injection (SSTI)
Moderate
CVE-2026-23626
was published
for
kimai/kimai
(Composer)
Jan 20, 2026
External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function
Critical
CVE-2026-22822
was published
for
github.com/external-secrets/external-secrets
(Go)
Jan 20, 2026
@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)
High
CVE-2026-22037
was published
for
@fastify/express
(npm)
Jan 20, 2026
Fastify Middie Middleware Path Bypass
High
CVE-2026-22031
was published
for
@fastify/middie
(npm)
Jan 20, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered
High
CVE-2026-21696
was published
for
github.com/pterodactyl/wings
(Go)
Jan 20, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks
High
CVE-2025-69199
was published
for
github.com/pterodactyl/wings
(Go)
Jan 20, 2026
Pterodactyl improperly locks resources allowing raced queries to create more resources than alloted
Moderate
CVE-2025-69198
was published
for
pterodactyl/panel
(Composer)
Jan 20, 2026
WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect
High
CVE-2025-68616
was published
for
weasyprint
(pip)
Jan 20, 2026
Keycloak’s OpenID Connect Dynamic Client Registration feature affected by Server-Side Request Forgery (SSRF)
Moderate
CVE-2026-1180
was published
for
org.keycloak:keycloak-adapter-core
(Maven)
Jan 20, 2026
MineAdmin improperly refreshes tokens
Low
CVE-2026-1195
was published
for
mineadmin/mineadmin
(Composer)
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
CVE-2026-1196
was published
for
mineadmin/mineadmin
(Composer)
Jan 20, 2026
ProTip!
Advisories are also available from the
GraphQL API