GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,460
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,142
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
361 advisories
Filter by severity
Apache Traffic Server truncates over-long header names, allowing header aliasing, request...
Critical
Unreviewed
CVE-2026-58155
was published
Jul 29, 2026
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue...
High
Unreviewed
CVE-2026-57834
was published
Jul 29, 2026
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade...
High
Unreviewed
CVE-2026-58150
was published
Jul 29, 2026
Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked...
Moderate
Unreviewed
CVE-2026-58153
was published
Jul 29, 2026
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in...
Moderate
Unreviewed
CVE-2026-24033
was published
Jul 29, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0...
High
Unreviewed
CVE-2026-15325
was published
Jul 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0...
High
Unreviewed
CVE-2026-15064
was published
Jul 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0...
High
Unreviewed
CVE-2026-15328
was published
Jul 28, 2026
Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote...
Moderate
Unreviewed
CVE-2026-67182
was published
Jul 28, 2026
tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote...
Moderate
Unreviewed
CVE-2026-66752
was published
Jul 28, 2026
Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote...
Moderate
Unreviewed
CVE-2026-67181
was published
Jul 28, 2026
A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing...
Moderate
Unreviewed
CVE-2026-66338
was published
Jul 25, 2026
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
High
GHSA-46q4-43ph-c6fr
was published
for
org.http4s:blaze-http_2.12
(Maven)
Jul 24, 2026
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
High
GHSA-mhvj-jhpq-885v
was published
for
org.http4s:blaze-http_2.13
(Maven)
Jul 24, 2026
swift-nio-http2: Missing CR/LF/NUL validation in header values
Moderate
CVE-2026-64785
was published
for
swift-nio-http2
(Swift)
Jul 24, 2026
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
Moderate
CVE-2026-59900
was published
for
io.netty:netty-codec-http2
(Maven)
Jul 22, 2026
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
Moderate
CVE-2026-59898
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed...
Moderate
Unreviewed
CVE-2026-12606
was published
Jul 14, 2026
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker...
Critical
Unreviewed
CVE-2026-27690
was published
Jul 14, 2026
mint: Content-Length header accepts non-RFC "+" sign prefix
Moderate
CVE-2026-49753
was published
for
mint
(Erlang)
Jul 9, 2026
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
High
CVE-2026-50197
was published
for
github.com/zalando/skipper
(Go)
Jul 8, 2026
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header...
Moderate
Unreviewed
CVE-2025-3110
was published
Jul 8, 2026
ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state,...
High
Unreviewed
CVE-2026-38969
was published
Jul 2, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0...
High
Unreviewed
CVE-2026-11541
was published
Jul 1, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary...
High
Unreviewed
CVE-2026-11806
was published
Jun 30, 2026
ProTip!
Advisories are also available from the
GraphQL API