GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
35,755 advisories
Filter by severity
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
Moderate
CVE-2026-75523
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Sep 17, 2026
Grav: Stored XSS via Markdown audio/video media <source> URL
Moderate
CVE-2026-75831
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
High
CVE-2026-86038
was published
for
@libp2p/gossipsub
(npm)
Sep 17, 2026
Grav: Stored XSS via quoted-attribute bypass in detectXss
Moderate
CVE-2026-72832
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target
Moderate
CVE-2026-85717
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
Moderate
CVE-2026-85720
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
High
CVE-2026-85721
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses
Low
CVE-2026-85716
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
High
CVE-2026-85756
was published
for
SSH.NET
(NuGet)
Sep 17, 2026
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
Moderate
CVE-2026-73245
was published
for
io.kestra:kestra
(Maven)
Sep 17, 2026
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Moderate
CVE-2026-69147
was published
for
vllm
(pip)
Sep 17, 2026
Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
High
CVE-2026-69089
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
High
CVE-2026-69088
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
Moderate
CVE-2026-85732
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
High
CVE-2026-85731
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
High
CVE-2026-73247
was published
for
io.kestra:core
(Maven)
Sep 17, 2026
Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
High
CVE-2026-65608
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)
High
CVE-2026-86043
was published
for
github.com/zalando/skipper
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client
High
CVE-2026-77412
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr
Critical
CVE-2026-77411
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation
High
CVE-2026-77410
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow
Critical
CVE-2026-77408
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields
High
CVE-2026-77407
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration
High
CVE-2026-77406
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser
Critical
CVE-2026-77405
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
ProTip!
Advisories are also available from the
GraphQL API