GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
33,868 advisories
Filter by severity
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
High
GHSA-6vch-q96h-7gc3
was published
for
go.etcd.io/etcd/v3
(Go)
Jul 24, 2026
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
Moderate
GHSA-8q49-2h5h-434x
was published
for
@frontmcp/adapters
(npm)
Jul 24, 2026
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
Moderate
GHSA-jpcw-4wr7-c3vq
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
High
CVE-2026-16796
was published
for
bedrock-agentcore
(pip)
Jul 24, 2026
etcd: Watch API authorization bypass via open-ended range requests
High
GHSA-xg4h-6gfc-h4m8
was published
for
go.etcd.io/etcd/v3
(Go)
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
CVE-2026-16756
was published
for
aws-smithy-http-server
(Rust)
Jul 24, 2026
libp2p: yamux connection DoS via oversized data frame
High
GHSA-hmj8-5xmh-5573
was published
for
libp2p
(pip)
Jul 24, 2026
Quasar: Prototype pollution in the extend() utility
Moderate
GHSA-3r53-75j5-3g7j
was published
for
quasar
(npm)
Jul 24, 2026
Oh My Posh: Arbitrary command execution via template injection in the path segment
High
GHSA-6xj8-qv9j-xcjq
was published
for
github.com/jandedobbeleer/oh-my-posh
(Go)
Jul 24, 2026
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Moderate
GHSA-fwjx-9p69-h25h
was published
for
github.com/jandedobbeleer/oh-my-posh
(Go)
Jul 24, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries
High
GHSA-fp43-vj7g-pg92
was published
for
org.omnifaces:omnifaces
(Maven)
Jul 24, 2026
Shescape: Quadratic-time denial of service in the flag-protection
High
GHSA-gm3r-q2wp-hw87
was published
for
shescape
(npm)
Jul 24, 2026
Shescape: Home-directory disclosure in assignment context on Unix with Dash
Moderate
GHSA-q53c-4prm-w95q
was published
for
shescape
(npm)
Jul 24, 2026
Shescape: Shell injection via unescaped parentheses on Windows with CMD
Critical
GHSA-w4hw-qcx7-56pr
was published
for
shescape
(npm)
Jul 24, 2026
Shescape: Path disclosure on Unix with Zsh
Moderate
GHSA-6v4m-fw66-8r4x
was published
for
shescape
(npm)
Jul 24, 2026
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
High
CVE-2026-16584
was published
for
awslabs.aws-api-mcp-server
(pip)
Jul 24, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
Moderate
GHSA-86cx-wwf4-phq4
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
Moderate
GHSA-p6ph-3jx2-3337
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
High
GHSA-95cv-r8x4-vh75
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
High
GHSA-7ppr-r889-mcf2
was published
for
org.http4s:http4s-blaze-server_2.12
(Maven)
Jul 24, 2026
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
High
GHSA-46q4-43ph-c6fr
was published
for
org.http4s:blaze-http_2.12
(Maven)
Jul 24, 2026
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
High
GHSA-mhvj-jhpq-885v
was published
for
org.http4s:blaze-http_2.13
(Maven)
Jul 24, 2026
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
High
GHSA-cmwh-g2h8-c222
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
High
GHSA-h4hf-v6w5-897x
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API