GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
33,673 advisories
Filter by severity
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
Moderate
GHSA-652q-gvq3-74qv
was published
for
n8n
(npm)
Jul 22, 2026
n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
Moderate
GHSA-jqwr-vx3p-r266
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
Moderate
GHSA-9cmh-xcqm-5hqr
was published
for
n8n
(npm)
Jul 22, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
High
GHSA-pppj-hq3g-57pj
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
High
GHSA-gx64-gj6p-pc4c
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Moderate
GHSA-89vp-jrxv-24w8
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Moderate
GHSA-h5v5-8746-g7mm
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
Low
GHSA-whvh-wf3x-g77j
was published
for
jupyterlab
(pip)
Jul 22, 2026
Next.js: Server-Side Request Forgery in Server Actions on custom servers
High
CVE-2026-64649
was published
for
next
(npm)
Jul 22, 2026
Next.js: Cache confusion of response bodies for requests with bodies
Moderate
CVE-2026-64648
was published
for
next
(npm)
Jul 22, 2026
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Moderate
CVE-2026-64647
was published
for
next
(npm)
Jul 22, 2026
Next.js: Unbounded Server Action payload in Edge runtime
Moderate
CVE-2026-64646
was published
for
next
(npm)
Jul 22, 2026
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
High
CVE-2026-64645
was published
for
next
(npm)
Jul 22, 2026
Next.js: Denial of Service in the Image Optimization API using SVGs
Moderate
CVE-2026-64644
was published
for
next
(npm)
Jul 22, 2026
Next.js: Unauthenticated disclosure of internal Server Function endpoints
Moderate
CVE-2026-64643
was published
for
next
(npm)
Jul 22, 2026
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
High
CVE-2026-64642
was published
for
next
(npm)
Jul 22, 2026
Next.js: Denial of Service in App Router using Server Actions
High
CVE-2026-64641
was published
for
next
(npm)
Jul 22, 2026
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
High
CVE-2024-7708
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
Eclipse Jetty: Path parameter traversal
Moderate
CVE-2026-8384
was published
for
org.eclipse.jetty:jetty-util
(Maven)
Jul 22, 2026
Eclipse Jetty: HTTP Authority/Host mismatch
Moderate
CVE-2026-6790
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
Moderate
CVE-2026-10051
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution
High
CVE-2026-10050
was published
for
org.eclipse.jetty.ee8:jetty-ee8-security
(Maven)
Jul 22, 2026
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Moderate
CVE-2026-65589
was published
for
n8n
(npm)
Jul 22, 2026
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
Moderate
CVE-2026-59943
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Moderate
CVE-2026-59942
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API