GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
7,104 advisories
Filter by severity
io.moquette:moquette-broker has a Missing Authorization issue
High
CVE-2026-85058
was published
for
io.moquette:moquette-broker
(Maven)
Sep 18, 2026
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
Critical
CVE-2025-53837
was published
for
org.xwiki.rendering:xwiki-rendering-xml
(Maven)
Sep 18, 2026
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text
High
CVE-2026-77615
was published
for
org.opencastproject:opencast-engage-paella-player-7
(Maven)
Sep 18, 2026
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
High
CVE-2026-81876
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.r5
(Maven)
Sep 17, 2026
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
High
CVE-2026-81875
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.r5
(Maven)
Sep 17, 2026
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target
Moderate
CVE-2026-85717
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
Moderate
CVE-2026-85720
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
High
CVE-2026-85721
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses
Low
CVE-2026-85716
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
Moderate
CVE-2026-73245
was published
for
io.kestra:kestra
(Maven)
Sep 17, 2026
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
High
CVE-2026-73247
was published
for
io.kestra:core
(Maven)
Sep 17, 2026
Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root
Low
CVE-2026-86071
was published
for
com.github.junrar:junrar
(Maven)
Sep 17, 2026
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
Low
CVE-2026-61700
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Sep 17, 2026
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)
High
CVE-2026-63126
was published
for
com.squareup.wire:wire-runtime
(Maven)
Sep 17, 2026
RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement
High
CVE-2026-75516
was published
for
com.rabbitmq:amqp-client
(Maven)
Sep 17, 2026
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE
High
CVE-2026-88975
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators
Moderate
CVE-2026-69201
was published
for
org.http4s:http4s-server_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2: unbounded continuation frame accumulation
High
CVE-2026-69218
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: Ember chunk parser lenience (TE.TE request smuggling)
Moderate
CVE-2026-69216
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin
Moderate
CVE-2026-69215
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
Moderate
CVE-2026-69214
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2 has an unbounded outbound frame queue
High
CVE-2026-69213
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: DigestAuth nonce map grows unbounded
High
CVE-2026-69208
was published
for
org.http4s:http4s-ember-server_2.12
(Maven)
Sep 15, 2026
Http4s: DigestAuth allows replay of captured requests
Moderate
CVE-2026-69206
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)
High
CVE-2026-69205
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
ProTip!
Advisories are also available from the
GraphQL API