GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
19 advisories
Filter by severity
Gogs's write-level collaborators can mutate admin-only repository settings via API
High
CVE-2026-52808
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
High
CVE-2026-50285
was published
for
github.com/pomerium/pomerium
(Go)
Jul 15, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
High
CVE-2026-49478
was published
for
github.com/sigstore/fulcio
(Go)
Jun 30, 2026
Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit
High
CVE-2026-27806
was published
for
github.com/fleetdm/fleet/v4
(Go)
Apr 8, 2026
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
High
CVE-2026-45022
was published
for
github.com/go-git/go-git/v5
(Go)
May 11, 2026
Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)
High
CVE-2026-45090
was published
for
github.com/hahwul/dalfox
(Go)
May 12, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService
High
CVE-2026-45726
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token
High
CVE-2026-45720
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
Typebot has Stored XSS via Rating Block Custom Icon that Bypasses isUnsafe Sandbox in Builder Preview
High
CVE-2026-28445
was published
for
@typebot.io/js
(npm)
May 26, 2026
vm2 has a NodeVM require.root bypass via symlink traversal that allows sandbox escape
High
CVE-2026-43998
was published
for
vm2
(npm)
May 7, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write
High
CVE-2026-42275
was published
for
github.com/openziti/zrok
(Go)
Apr 25, 2026
Directus: TUS Upload Authorization Bypass Allows Arbitrary File Overwrite
High
CVE-2026-35412
was published
for
directus
(npm)
Apr 4, 2026
Directus: Unauthenticated Denial of Service via GraphQL Alias Amplification of Expensive Health Check Resolver
High
GHSA-6q22-g298-grjh
was published
for
directus
(npm)
Apr 4, 2026
Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write
High
CVE-2026-35214
was published
for
@budibase/server
(npm)
Apr 4, 2026
lodash vulnerable to Code Injection via `_.template` imports key names
High
CVE-2026-4800
was published
for
lodash
(npm)
Apr 1, 2026
parse-server has GraphQL complexity validator exponential fragment traversal DoS
High
CVE-2026-34573
was published
for
parse-server
(npm)
Mar 31, 2026
AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
High
CVE-2026-33039
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments
High
CVE-2026-33038
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
AVideo: Unauthenticated PHP session store exposed to host network via published memcached port
High
CVE-2026-29093
was published
for
wwbn/avideo
(Composer)
Mar 5, 2026
ProTip!
Advisories are also available from the
GraphQL API