GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,407 advisories
Filter by severity
Gin-vue-admin has arbitrary file upload vulnerability caused by path traversal
High
CVE-2026-22786
was published
for
github.com/flipped-aurora/gin-vue-admin
(Go)
Jan 13, 2026
orval MCP client is vulnerable to a code injection attack.
Critical
CVE-2026-22785
was published
for
@orval/mcp
(npm)
Jan 13, 2026
ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler
High
CVE-2026-22777
was published
for
comfy-cli
(pip)
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
Critical
CVE-2025-68271
was published
for
openc3
(RubyGems)
Jan 13, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
Moderate
CVE-2026-22772
was published
for
github.com/sigstore/fulcio
(Go)
Jan 13, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution
High
CVE-2026-22771
was published
for
github.com/envoyproxy/gateway
(Go)
Jan 13, 2026
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
Moderate
CVE-2026-22702
was published
for
virtualenv
(pip)
Jan 13, 2026
filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock
Moderate
CVE-2026-22701
was published
for
filelock
(pip)
Jan 13, 2026
vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions
Moderate
CVE-2026-22773
was published
for
vllm
(pip)
Jan 13, 2026
Mailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to emails
Moderate
CVE-2026-22689
was published
for
github.com/axllent/mailpit
(Go)
Jan 13, 2026
RustCrypto: Signatures has timing side-channel in ML-DSA decomposition
Moderate
CVE-2026-22705
was published
for
ml-dsa
(Rust)
Jan 13, 2026
HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover
High
CVE-2026-22704
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jan 13, 2026
RustCrypto Has Insufficient Length Validation in decrypt() in SM2-PKE
High
CVE-2026-22700
was published
for
sm2
(Rust)
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions
Moderate
CVE-2026-22703
was published
for
github.com/sigstore/cosign/v2
(Go)
Jan 13, 2026
n8n: Webhook Node IP Whitelist Bypass via Partial String Matching
Moderate
CVE-2025-68949
was published
for
n8n
(npm)
Jan 13, 2026
Jervis's AES CBC Mode is Without Authentication
High
CVE-2025-68931
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis Has a JWT Algorithm Confusion Vulnerability
Moderate
CVE-2025-68925
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis Has Weak Random for Timing Attack Mitigation
High
CVE-2025-68704
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis's Salt for PBKDF2 derived from password
High
CVE-2025-68703
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis Has a SHA-256 Hex String Padding Bug
High
CVE-2025-68702
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis has Deterministic AES IV Derivation from Passphrase
High
CVE-2025-68701
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis Has a RSA PKCS#1 Padding Vulnerability
High
CVE-2025-68698
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Weblate wlc has insecure API key configuration
Moderate
CVE-2026-22251
was published
for
wlc
(pip)
Jan 12, 2026
Weblate command-line client susceptible to SSL verification skip
Low
CVE-2026-22250
was published
for
wlc
(pip)
Jan 12, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
High
CVE-2026-22033
was published
for
label-studio
(pip)
Jan 12, 2026
ProTip!
Advisories are also available from the
GraphQL API