GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
48
Go
3,404
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,632
Pub
13
RubyGems
1,026
Rust
1,205
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,350 advisories
Filter by severity
Cloudfoundry UAA has logic error in the token revocation endpoint implementation
Moderate
CVE-2026-22723
was published
for
org.cloudfoundry.identity:cloudfoundry-identity-server
(Maven)
Mar 5, 2026
@perfood/couch-auth has an Observable Timing Discrepancy
High
CVE-2025-70949
was published
for
@perfood/couch-auth
(npm)
Mar 5, 2026
@perfood/couch-auth has a host header injection vulnerability
Moderate
CVE-2025-70948
was published
for
@perfood/couch-auth
(npm)
Mar 5, 2026
Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
High
CVE-2026-3009
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 5, 2026
Fonoster is vulnerable to directory traversal
Moderate
CVE-2024-43035
was published
for
@fonoster/voice
(npm)
Mar 5, 2026
Keycloak SAML Broken has Authentication Bypass by Primary Weakness
High
CVE-2026-3047
was published
for
org.keycloak:keycloak-broker-saml
(Maven)
Mar 5, 2026
RAGAS has an Arbitrary File Read vulnerability
High
CVE-2025-45691
was published
for
ragas
(pip)
Mar 5, 2026
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
Moderate
CVE-2026-3419
was published
for
fastify
(npm)
Mar 5, 2026
The Eclipse Jetty Server Artifact has a Gzip request memory leak
High
CVE-2026-1605
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Mar 5, 2026
OliveTin doesn't check view permission when returning dashboards
Moderate
CVE-2026-30233
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
`time-sync` was removed from crates.io due to malicious code
Critical
GHSA-mh23-rw7f-v5pq
was published
for
time-sync
(Rust)
Mar 5, 2026
EC-CUBE has a Vulnerability that Allows MFA Bypass in the Administrative Interface
Moderate
GHSA-7rhv-h82h-vpjh
was published
for
ec-cube/ec-cube
(Composer)
Mar 5, 2026
Pingora vulnerable to cache poisoning via insecure-by-default cache key
High
CVE-2026-2836
was published
for
pingora-cache
(Rust)
Mar 5, 2026
Pingora has HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
Critical
CVE-2026-2835
was published
for
pingora-core
(Rust)
Mar 5, 2026
Pingora vulnerable to HTTP Request Smuggling via Premature Upgrade
Critical
CVE-2026-2833
was published
for
pingora-core
(Rust)
Mar 5, 2026
OliveTin has crash on NPE by calling APIs with invalid bindings or log references
Moderate
GHSA-fwhj-785h-43hh
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
OliveTin's RestartAction always runs actions as guest
Moderate
CVE-2026-30225
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
OliveTin Session Fixation: Logout Fails to Invalidate Server-Side Session
Moderate
CVE-2026-30224
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
OliveTin has JWT Audience Validation Bypass in Local Key and HMAC Modes
High
CVE-2026-30223
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
stellar-xdr's StringM::from_str bypasses max length validation
Moderate
CVE-2026-29795
was published
for
stellar-xdr
(Rust)
Mar 5, 2026
Gokapi has CSRF in Login Endpoint
Moderate
CVE-2026-29084
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion
Moderate
CVE-2026-29061
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
LangGraph checkpoint loading has unsafe msgpack deserialization
Moderate
CVE-2026-28277
was published
for
langgraph
(pip)
Mar 5, 2026
Gogs: DOM-based XSS via milestone selection
High
CVE-2026-26276
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gogs: Access tokens get exposed through URL params in API requests
Moderate
CVE-2026-26196
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
ProTip!
Advisories are also available from the
GraphQL API