GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,049
pip
5,000+
Pub
13
RubyGems
1,128
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
33,693 advisories
Filter by severity
Ruby json: JSON generator heap buffer overflow when streaming to an IO
Low
CVE-2026-54696
was published
for
json
(RubyGems)
Jul 23, 2026
c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets
Moderate
CVE-2026-55223
was published
for
com.mchange:c3p0
(Maven)
Jul 23, 2026
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
Moderate
CVE-2026-53669
was published
for
react-router
(npm)
Jul 23, 2026
React Router: Open redirect leading to XSS
Moderate
CVE-2026-53668
was published
for
react-router
(npm)
Jul 23, 2026
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
Moderate
CVE-2026-53667
was published
for
react-router
(npm)
Jul 23, 2026
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
Moderate
CVE-2026-53666
was published
for
react-router
(npm)
Jul 23, 2026
ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
Moderate
CVE-2026-53467
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 23, 2026
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
High
CVE-2026-59935
was published
for
pypdf
(pip)
Jul 23, 2026
pypdf: Possible infinite loop for not terminated inline images
High
CVE-2026-59936
was published
for
pypdf
(pip)
Jul 23, 2026
pypdf: Possible long runtimes for repeated malformed cross-reference entries
Moderate
CVE-2026-59937
was published
for
pypdf
(pip)
Jul 23, 2026
pypdf: Possible large memory usage for wrong image dimensions
Moderate
CVE-2026-59938
was published
for
pypdf
(pip)
Jul 23, 2026
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
High
CVE-2026-45623
was published
for
postcss
(npm)
Jul 23, 2026
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
High
CVE-2026-59933
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
High
CVE-2026-59932
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
High
CVE-2026-59931
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Critical
GHSA-8fpg-xm3f-6cx3
was published
for
next-auth
(npm)
Jul 23, 2026
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
High
GHSA-xmf8-cvqr-rfgj
was published
for
@auth/core
(npm)
Jul 23, 2026
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Critical
GHSA-7rqj-j65f-68wh
was published
for
@auth/core
(npm)
Jul 23, 2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Moderate
GHSA-x445-f3h2-j279
was published
for
@auth/core
(npm)
Jul 23, 2026
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
Moderate
GHSA-652q-gvq3-74qv
was published
for
n8n
(npm)
Jul 22, 2026
n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
Moderate
GHSA-jqwr-vx3p-r266
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
Moderate
GHSA-9cmh-xcqm-5hqr
was published
for
n8n
(npm)
Jul 22, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
High
GHSA-pppj-hq3g-57pj
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
High
GHSA-gx64-gj6p-pc4c
was published
for
jupyterlab
(pip)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API