GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
35,755 advisories
Filter by severity
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection
High
CVE-2026-77404
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation
High
CVE-2026-77403
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root
Low
CVE-2026-86071
was published
for
com.github.junrar:junrar
(Maven)
Sep 17, 2026
Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions
Moderate
CVE-2026-77401
was published
for
AccessControl
(pip)
Sep 17, 2026
RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution
High
CVE-2026-76825
was published
for
RestrictedPython
(pip)
Sep 17, 2026
ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion
High
CVE-2026-85715
was published
for
exifreader
(npm)
Sep 17, 2026
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
Low
CVE-2026-61700
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Sep 17, 2026
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
High
CVE-2026-69197
was published
for
Umbraco.Cms
(NuGet)
Sep 17, 2026
sanic chunked trailer request smuggling allows hidden second request execution
Moderate
CVE-2026-85078
was published
for
sanic
(pip)
Sep 17, 2026
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
High
CVE-2026-63506
was published
for
@tinacms/auth
(npm)
Sep 17, 2026
Redocly CLI: Path traversal when using `split` command
Moderate
CVE-2026-63225
was published
for
@redocly/cli
(npm)
Sep 17, 2026
Pocketbase: Unhandled panic in worker goroutines
High
CVE-2026-82410
was published
for
github.com/pocketbase/pocketbase
(Go)
Sep 17, 2026
Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
Moderate
CVE-2026-61449
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
Moderate
CVE-2026-62949
was published
for
asyncssh
(pip)
Sep 17, 2026
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)
High
CVE-2026-63126
was published
for
com.squareup.wire:wire-runtime
(Maven)
Sep 17, 2026
oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
Moderate
CVE-2026-77360
was published
for
@orpc/server
(npm)
Sep 17, 2026
RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement
High
CVE-2026-75516
was published
for
com.rabbitmq:amqp-client
(Maven)
Sep 17, 2026
Marten's LINQ provider has SQL injection via unescaped string literals
Critical
CVE-2026-75513
was published
for
Marten
(NuGet)
Sep 17, 2026
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
Moderate
CVE-2026-59823
was published
for
litellm
(pip)
Sep 17, 2026
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows
High
CVE-2026-71538
was published
for
@cyclonedx/cyclonedx-npm
(npm)
Sep 17, 2026
Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
Critical
CVE-2026-63472
was published
for
@vendure/core
(npm)
Sep 17, 2026
Vendure: Shop API list queries can return non-public entities when filterOperator is OR
Moderate
CVE-2026-63461
was published
for
@vendure/core
(npm)
Sep 17, 2026
Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends
High
CVE-2026-63460
was published
for
vendure/core
(npm)
Sep 17, 2026
Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
High
CVE-2026-63459
was published
for
@vendure/dashboard
(npm)
Sep 17, 2026
Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter
Moderate
CVE-2026-61793
was published
for
nuxt-og-image
(npm)
Sep 17, 2026
ProTip!
Advisories are also available from the
GraphQL API