GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
6,455 advisories
Filter by severity
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
Moderate
CVE-2026-64663
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Statamic: Account takeover via OAuth email matching without email-verification check
High
CVE-2026-64665
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
Moderate
CVE-2026-64664
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering
Moderate
CVE-2026-71293
was published
for
statamic/cms
(Composer)
Aug 5, 2026
Guzzle: Noncanonical host can bypass host-based checks
High
CVE-2026-69246
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
Guzzle: Noncanonical cookie domain keeps subdomain scope
Moderate
CVE-2026-69245
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
High
GHSA-mqq9-gxg5-m58g
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
Moderate
GHSA-3fvr-2jw6-crq4
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
High
GHSA-mjrx-74jh-7xgw
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
Moderate
GHSA-32rq-jhr7-m3hh
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)
Moderate
CVE-2026-54768
was published
for
wp-graphql/wp-graphql
(Composer)
Jul 31, 2026
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
High
CVE-2026-53599
was published
for
redaxo/source
(Composer)
Jul 31, 2026
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
Moderate
CVE-2026-68501
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
High
CVE-2026-68500
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
Low
CVE-2026-52838
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
Low
CVE-2026-52841
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Moderate
CVE-2026-52837
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Low
CVE-2026-52839
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Low
CVE-2026-52840
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
High
CVE-2026-55651
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
Critical
CVE-2026-54588
was published
for
poweradmin/poweradmin
(Composer)
Jul 28, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
High
CVE-2026-54593
was published
for
github.com/pterodactyl/wings
(Composer)
Jul 28, 2026
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
High
CVE-2026-61609
was published
for
pterodactyl/panel
(Composer)
Jul 28, 2026
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability
High
CVE-2026-45293
was published
for
wp-coding-standards/wpcs
(Composer)
Jul 28, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
CVE-2026-43871
was published
for
apache/thrift
(Composer)
Jul 27, 2026
ProTip!
Advisories are also available from the
GraphQL API