GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,579
Rust
21
416 advisories
Filter by severity
When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without...
High
Unreviewed
CVE-2026-94439
was published
Oct 9, 2026
When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the...
High
Unreviewed
CVE-2026-56866
was published
Oct 9, 2026
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can...
High
Unreviewed
CVE-2018-12116
was published
May 13, 2022
pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in...
Critical
Unreviewed
CVE-2026-37604
was published
Sep 22, 2026
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end...
Low
Unreviewed
CVE-2026-77803
was published
Oct 5, 2026
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP...
Moderate
Unreviewed
CVE-2026-77802
was published
Oct 5, 2026
Apache Tomcat Improper Input Validation vulnerability
High
CVE-2023-46589
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Nov 28, 2023
Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
Moderate
CVE-2025-71381
was published
for
hono
(npm)
Oct 24, 2025
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response...
High
Unreviewed
CVE-2026-63718
was published
Oct 1, 2026
A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect:...
Moderate
Unreviewed
CVE-2026-103399
was published
Sep 30, 2026
undici vulnerable to downstream response splitting via retry interceptor
Low
CVE-2026-18540
was published
for
undici
(npm)
Sep 29, 2026
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in...
Critical
Unreviewed
CVE-2026-88773
was published
Sep 27, 2026
http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses...
Moderate
Unreviewed
CVE-2026-100724
was published
Sep 27, 2026
Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final...
Moderate
Unreviewed
CVE-2026-100659
was published
Sep 26, 2026
Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final...
Moderate
Unreviewed
CVE-2026-100666
was published
Sep 26, 2026
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
High
CVE-2026-65838
was published
for
github.com/zalando/skipper
(Go)
Jul 17, 2026
http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`
Moderate
GHSA-jrpc-7vxp-69p6
was published
for
org.http4k:http4k-core
(Maven)
Jun 19, 2026
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in...
Low
Unreviewed
CVE-2026-77756
was published
Sep 23, 2026
Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability...
Unknown
Unreviewed
CVE-2026-86350
was published
Sep 23, 2026
Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling
Moderate
Unreviewed
CVE-2026-93573
was published
Sep 18, 2026
A maliciously constructed mail header could lead to multiple fields being parsed as one, or...
Critical
Unreviewed
CVE-2026-92238
was published
Sep 15, 2026
HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request...
High
Unreviewed
CVE-2026-93569
was published
Sep 18, 2026
A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this...
Moderate
Unreviewed
CVE-2026-93574
was published
Sep 18, 2026
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by...
Moderate
Unreviewed
CVE-2026-14180
was published
Aug 11, 2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP...
Moderate
Unreviewed
CVE-2026-11548
was published
Sep 18, 2026
ProTip!
Advisories are also available from the
GraphQL API