GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
136 advisories
Filter by severity
github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar...
Moderate
Unreviewed
CVE-2026-80051
was published
Aug 25, 2026
An ACAP configuration file lacks input validation, which could potentially lead to privilege...
Moderate
Unreviewed
CVE-2026-5304
was published
Aug 11, 2026
Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated...
High
Unreviewed
CVE-2026-18830
was published
Aug 4, 2026
In geniezone, there is a possible escalation of privilege due to a missing permission check. This...
Moderate
Unreviewed
CVE-2026-20498
was published
Aug 3, 2026
Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM...
High
Unreviewed
CVE-2026-4773
was published
Jul 22, 2026
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
High
CVE-2026-50524
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB read
Moderate
CVE-2026-52763
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
High
CVE-2026-2092
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 2, 2026
vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
Moderate
CVE-2026-54235
was published
for
vllm
(pip)
Jun 17, 2026
A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and...
High
Unreviewed
CVE-2026-10825
was published
Jun 16, 2026
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff...
High
Unreviewed
CVE-2026-9753
was published
Jun 10, 2026
When OIDC authentication is enabled in configuration, clients may set specific values in the ...
High
Unreviewed
CVE-2026-9742
was published
Jun 10, 2026
In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to...
Moderate
Unreviewed
CVE-2024-6858
was published
Jun 5, 2026
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
Moderate
CVE-2026-47675
was published
for
hono
(npm)
Jun 4, 2026
Symfony's OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims
Moderate
CVE-2026-45069
was published
for
symfony/security-http
(Composer)
May 27, 2026
A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on...
High
Unreviewed
CVE-2026-40851
was published
May 27, 2026
Mattermost doesn't validate user-supplied input in API request handlers
Moderate
CVE-2026-4646
was published
for
github.com/mattermost/mattermost-plugin-github
(Go)
May 26, 2026
Concrete CMS: OAuth 2.0 Authorization-Code Handler Bypasses Account Status
Low
CVE-2026-7887
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Multiple flaws have been identified in `named` related to the handling of DNS messages whose...
High
Unreviewed
CVE-2026-5946
was published
May 20, 2026
An ACAP configuration file lacked sufficient input validation, which could allow command...
Moderate
Unreviewed
CVE-2026-0802
was published
May 12, 2026
Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header
High
CVE-2026-33806
was published
for
fastify
(npm)
Apr 15, 2026
TSPortal: Any user can forge self-deletion requests for any account
High
CVE-2026-29788
was published
for
miraheze/ts-portal
(Composer)
Mar 27, 2026
jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs
High
CVE-2026-4598
was published
for
jsrsasign
(npm)
Mar 23, 2026
SpotAuditor 5.2.6 contains a denial of service vulnerability in the registration dialog that...
Moderate
Unreviewed
CVE-2019-25596
was published
Mar 22, 2026
Duplicate Advisory: Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
High
GHSA-wmxr-6j5f-838p
was published
for
org.keycloak:keycloak-saml-adapter-core
(Maven)
Mar 18, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API