GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
61 advisories
Filter by severity
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
High
CVE-2026-55641
was published
for
9router
(npm)
Aug 28, 2026
CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
Moderate
CVE-2026-63220
was published
for
codeigniter4/framework
(Composer)
Aug 7, 2026
In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the ...
Moderate
Unreviewed
CVE-2026-50243
was published
Jul 22, 2026
Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
Moderate
CVE-2026-59897
was published
for
hono
(npm)
Jul 21, 2026
FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that...
High
Unreviewed
CVE-2026-64619
was published
Jul 20, 2026
Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler...
High
Unreviewed
CVE-2026-63770
was published
Jul 20, 2026
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows...
Critical
Unreviewed
CVE-2026-58122
was published
Jul 10, 2026
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over...
Moderate
Unreviewed
CVE-2026-59999
was published
Jul 8, 2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0...
Low
Unreviewed
CVE-2026-46466
was published
Jul 3, 2026
LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in...
Moderate
Unreviewed
CVE-2026-57942
was published
Jun 29, 2026
chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header
High
GHSA-rjr7-jggh-pgcp
was published
for
github.com/go-chi/chi/middleware
(Go)
Jun 25, 2026
An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active...
Critical
Unreviewed
CVE-2026-12249
was published
Jun 22, 2026
Use of Less Trusted Source vulnerability in Apache APISIX.
Attacker can take advantage of wolf...
Low
Unreviewed
CVE-2026-44046
was published
Jun 19, 2026
hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
Moderate
CVE-2026-54289
was published
for
hono
(npm)
Jun 16, 2026
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
Moderate
CVE-2026-48061
was published
for
litestar
(pip)
Jun 10, 2026
OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication...
Moderate
Unreviewed
CVE-2020-37248
was published
Jun 8, 2026
Caddy Defender trusted proxy client IP bypass
High
CVE-2026-46415
was published
for
pkg.jsn.cam/caddy-defender
(Go)
May 19, 2026
HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows...
High
Unreviewed
CVE-2026-43634
was published
May 19, 2026
In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted...
Moderate
Unreviewed
CVE-2026-40226
was published
Apr 10, 2026
Shynet before 0.14.0 allows Host header injection in the password reset flow.
Moderate
Unreviewed
CVE-2026-35507
was published
Apr 3, 2026
OpenClaw: diffs viewer misclassifies proxied remote requests as loopback when `allowRemoteViewer` is disabled
Moderate
CVE-2026-41403
was published
for
openclaw
(npm)
Apr 3, 2026
Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the...
Moderate
Unreviewed
CVE-2026-26927
was published
Apr 2, 2026
AVideo vulnerable to IP Address Spoofing via Untrusted HTTP Headers in getRealIpAddr()
Moderate
CVE-2026-33690
was published
for
wwbn/avideo
(Composer)
Mar 25, 2026
fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections
Moderate
CVE-2026-3635
was published
for
fastify
(npm)
Mar 25, 2026
Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker...
High
Unreviewed
CVE-2025-69240
was published
Mar 16, 2026
ProTip!
Advisories are also available from the
GraphQL API