GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,343
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,550
Pub
12
RubyGems
1,013
Rust
1,203
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,945 advisories
Filter by severity
Duplicate Advisory: OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes
Critical
GHSA-x49q-fhhm-r9jf
was published
for
openclaw
(npm)
Mar 20, 2026
•
withdrawn
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers
Moderate
CVE-2026-29794
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
Spring MVC and WebFlux has Server Sent Event stream corruption
Low
CVE-2026-22735
was published
for
org.springframework:spring-webflux
(Maven)
Mar 20, 2026
Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
High
CVE-2026-22733
was published
for
org.springframework.boot:spring-boot-starter-actuator
(Maven)
Mar 20, 2026
Spring Boot has an Authentication Bypass under Actuator Health groups paths
High
CVE-2026-22731
was published
for
org.springframework.boot:spring-boot-starter-actuator
(Maven)
Mar 20, 2026
Spring Security HTTP Headers Are not Written Under Some Conditions
Critical
CVE-2026-22732
was published
for
org.springframework.security:spring-security-web
(Maven)
Mar 20, 2026
ingress-nginx comment-based nginx configuration injection
High
CVE-2026-4342
was published
for
k8s.io/ingress-nginx
(Go)
Mar 20, 2026
Spring Framework Improper Path Limitation with Script View Templates
Moderate
CVE-2026-22737
was published
for
org.springframework:spring-webflux
(Maven)
Mar 20, 2026
Parse Server has an auth provider validation bypass on login via partial authData
High
CVE-2026-33409
was published
for
parse-server
(npm)
Mar 19, 2026
Scriban Affected by Memory Exhaustion (OOM) via Unbounded String Generation (Denial of Service)
Moderate
GHSA-5rpf-x9jg-8j5p
was published
for
scriban
(NuGet)
Mar 19, 2026
Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)
High
GHSA-grr9-747v-xvcp
was published
for
scriban
(NuGet)
Mar 19, 2026
Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)
High
GHSA-wgh7-7m3c-fx25
was published
for
scriban
(NuGet)
Mar 19, 2026
Protocol-Relative URL Injection via Single Backslash Bypass in Angular SSR
Moderate
CVE-2026-33397
was published
for
@angular/ssr
(npm)
Mar 19, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
Moderate
CVE-2026-4267
was published
for
johnbillion/query-monitor
(Composer)
Mar 19, 2026
AVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php`
High
CVE-2026-33354
was published
for
wwbn/avideo
(Composer)
Mar 19, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories
High
CVE-2026-33353
was published
for
github.com/charmbracelet/soft-serve
(Go)
Mar 19, 2026
AVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escape Bypass)
Critical
CVE-2026-33352
was published
for
wwbn/avideo
(Composer)
Mar 19, 2026
Dagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAG
High
CVE-2026-33344
was published
for
github.com/dagu-org/dagu
(Go)
Mar 19, 2026
AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification Bypass
Critical
CVE-2026-33351
was published
for
wwbn/avideo
(Composer)
Mar 19, 2026
Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser
Moderate
CVE-2026-33349
was published
for
fast-xml-parser
(npm)
Mar 19, 2026
league/commonmark has an embed extension allowed_domains bypass
Moderate
CVE-2026-33347
was published
for
league/commonmark
(Composer)
Mar 19, 2026
NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustion
Moderate
CVE-2026-33332
was published
for
nicegui
(pip)
Mar 19, 2026
@keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany (CVE-2025-46720 incomplete fix)
Moderate
CVE-2026-33326
was published
for
@keystone-6/core
(npm)
Mar 19, 2026
Packetbeat does not properly validate an array index in multiple protocol parser components
Moderate
CVE-2026-26933
was published
for
github.com/elastic/beats/v7
(Go)
Mar 19, 2026
PyMuPDF has a path traversal in _main_.py
Moderate
CVE-2026-3029
was published
for
PyMuPDF
(pip)
Mar 19, 2026
ProTip!
Advisories are also available from the
GraphQL API