GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
35,755 advisories
Filter by severity
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
Critical
CVE-2026-61559
was published
for
@zereight/mcp-gitlab
(npm)
Sep 15, 2026
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
Critical
CVE-2026-61568
was published
for
@zereight/mcp-gitlab
(npm)
Sep 15, 2026
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
High
GHSA-5648-rgj9-v224
was published
for
@zereight/mcp-gitlab
(npm)
Sep 15, 2026
emp3r0r has an unauthenticated HTTP Polling DoS
High
CVE-2026-61554
was published
for
github.com/jm33-m0/emp3r0r/core
(Go)
Sep 15, 2026
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE
High
CVE-2026-88975
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
High
CVE-2026-61544
was published
for
libp2p-quic
(Rust)
Sep 15, 2026
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators
Moderate
CVE-2026-69201
was published
for
org.http4s:http4s-server_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2: unbounded continuation frame accumulation
High
CVE-2026-69218
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: Ember chunk parser lenience (TE.TE request smuggling)
Moderate
CVE-2026-69216
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin
Moderate
CVE-2026-69215
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
Moderate
CVE-2026-69214
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2 has an unbounded outbound frame queue
High
CVE-2026-69213
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: DigestAuth nonce map grows unbounded
High
CVE-2026-69208
was published
for
org.http4s:http4s-ember-server_2.12
(Maven)
Sep 15, 2026
Http4s: DigestAuth allows replay of captured requests
Moderate
CVE-2026-69206
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)
High
CVE-2026-69205
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
Critical
CVE-2026-69204
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
High
CVE-2026-69203
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2: unbounded inbound body buffering
High
CVE-2026-69202
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
Low
GHSA-rf68-8gjr-36q7
was published
for
github.com/nezhahq/nezha
(Go)
Sep 15, 2026
Netmaker has a boolean‑based SQL Injection
Moderate
CVE-2026-32599
was published
for
github.com/gravitl/netmaker
(Go)
Sep 15, 2026
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
Moderate
CVE-2026-76081
was published
for
github.com/zitadel/zitadel
(Go)
Sep 14, 2026
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
High
CVE-2026-56668
was published
for
github.com/zitadel/zitadel
(Go)
Sep 14, 2026
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
Critical
CVE-2026-59178
was published
for
esphome-device-builder
(pip)
Sep 14, 2026
October CMS: Incomplete Scheme Validation in Image Resizer
Low
GHSA-2xmm-m4wv-3fjh
was published
for
october/october
(Composer)
Sep 14, 2026
October CMS: PHP Object Injection via Backend Widget Session Storage
Low
CVE-2026-49400
was published
for
october/system
(Composer)
Sep 14, 2026
ProTip!
Advisories are also available from the
GraphQL API