GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
48
GitHub Actions
48
Go
3,393
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,614
Pub
13
RubyGems
1,026
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
28,242 advisories
Filter by severity
Improper detection of disallowed URIs by Loofah `allowed_uri?`
Low
GHSA-46fp-8f5p-pf2m
was published
for
loofah
(RubyGems)
Mar 18, 2026
Out-of-Bounds Slice Access in free5GC CHF Leading to DoS
High
CVE-2026-32937
was published
for
github.com/free5gc/chf
(Go)
Mar 18, 2026
socket.io allows an unbounded number of binary attachments
High
CVE-2026-33151
was published
for
socket.io-parser
(npm)
Mar 18, 2026
Zitadel is missing enforcement of organization scopes
Moderate
CVE-2026-33132
was published
for
github.com/zitadel/zitadel
(Go)
Mar 18, 2026
OneUptime WhatsApp Webhook Missing Signature Verification
High
CVE-2026-33143
was published
for
oneuptime
(npm)
Mar 18, 2026
OneUptime ClickHouse vulnerable to SQL Injection via unvalidated column identifiers in sort, select, and groupBy parameters
High
CVE-2026-33142
was published
for
oneuptime
(npm)
Mar 18, 2026
PinchTab has a Blind SSRF via browser-side redirect bypass in /download URL validation
Moderate
CVE-2026-33081
was published
for
github.com/pinchtab/pinchtab
(Go)
Mar 18, 2026
Stored XSS in PySpector HTML Report Generation leads to Javascript Code Execution
Moderate
CVE-2026-33140
was published
for
pyspector
(pip)
Mar 18, 2026
PySpector has a Plugin Sandbox Bypass leads to Arbitrary Code Execution
High
CVE-2026-33139
was published
for
pyspector
(pip)
Mar 18, 2026
h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read
Moderate
GHSA-wr4h-v87w-p3r7
was published
for
h3
(npm)
Mar 18, 2026
h3 has a middleware bypass with one gadget
High
CVE-2026-33131
was published
for
h3
(npm)
Mar 18, 2026
h3 has an observable timing discrepancy in basic auth utils
Moderate
CVE-2026-33129
was published
for
h3
(npm)
Mar 18, 2026
h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields
High
CVE-2026-33128
was published
for
h3
(npm)
Mar 18, 2026
pypdf has inefficient decoding of array-based streams
Moderate
CVE-2026-33123
was published
for
pypdf
(pip)
Mar 18, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Moderate
CVE-2026-1323
was published
for
cpsit/typo3-mailqueue
(Composer)
Mar 18, 2026
Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemas
Moderate
GHSA-87v3-4cfp-cm76
was published
for
@pdfme/schemas
(npm)
Mar 18, 2026
Cross-Site Scripting (XSS) via Select Schema Option Value Injection in @pdfme/schemas
Moderate
GHSA-qq9g-96v4-m3cj
was published
for
@pdfme/schemas
(npm)
Mar 18, 2026
Capgo CLI: symlink-following local secret writes enable arbitrary file overwrite + world-readable credentials (0600 missing)
High
GHSA-8mpm-q7mh-8fvh
was published
for
@capgo/cli
(npm)
Mar 18, 2026
SiYuan has Stored XSS to RCE via Unsanitized Bazaar Package Metadata
Moderate
CVE-2026-33067
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 18, 2026
SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
Moderate
CVE-2026-33066
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 18, 2026
Frigte has broken access control viewer user can delete admin and other users account
High
CVE-2026-33125
was published
for
frigate
(pip)
Mar 18, 2026
UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
High
CVE-2026-32875
was published
for
ujson
(pip)
Mar 18, 2026
UltraJSON has a Memory Leak parsing large integers allows DoS
High
CVE-2026-32874
was published
for
ujson
(pip)
Mar 18, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string
High
CVE-2026-32811
was published
for
github.com/dadrus/heimdall
(Go)
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
High
CVE-2026-32286
was published
for
github.com/jackc/pgproto3/v2
(Go)
Mar 18, 2026
ProTip!
Advisories are also available from the
GraphQL API