GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,554 advisories
Filter by severity
Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on...
Moderate
Unreviewed
CVE-2026-85676
was published
Sep 4, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
Critical
CVE-2026-71428
was published
for
unstructured
(pip)
Sep 3, 2026
Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL...
Moderate
Unreviewed
CVE-2026-84662
was published
Sep 2, 2026
reset_password.html parses query string parameters and uses the 'url' parameter as a redirection...
Moderate
Unreviewed
CVE-2026-53683
was published
Sep 2, 2026
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could...
Moderate
Unreviewed
CVE-2026-73734
was published
Sep 1, 2026
Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate <...
Moderate
Unreviewed
CVE-2026-78079
was published
Aug 31, 2026
NSP is vulnerable to an open redirect due to insufficient server-side validation of the URL (or...
Moderate
Unreviewed
CVE-2026-40465
was published
Aug 31, 2026
pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform()...
Moderate
Unreviewed
CVE-2026-82464
was published
Aug 29, 2026
Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password,...
Moderate
Unreviewed
CVE-2026-82467
was published
Aug 29, 2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect...
Moderate
Unreviewed
CVE-2026-81342
was published
Aug 29, 2026
Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController...
Moderate
Unreviewed
CVE-2026-82274
was published
Aug 28, 2026
Snipe-IT has an Open Redirect After User Edit
Moderate
CVE-2026-55461
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
Moderate
CVE-2026-55834
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Aug 28, 2026
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
Moderate
CVE-2026-54770
was published
for
webob
(pip)
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
Low
CVE-2026-42350
was published
for
github.com/akuity/kargo
(Go)
Aug 27, 2026
In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint...
Moderate
Unreviewed
CVE-2026-59355
was published
Aug 27, 2026
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching...
Moderate
Unreviewed
CVE-2026-47883
was published
Aug 27, 2026
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path,...
Moderate
Unreviewed
CVE-2026-47887
was published
Aug 27, 2026
In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor...
Moderate
Unreviewed
CVE-2026-47848
was published
Aug 26, 2026
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued...
High
Unreviewed
CVE-2026-81029
was published
Aug 26, 2026
Stalwart Mail Server does not compare an OAuth redirect target against any registered destination...
High
Unreviewed
CVE-2026-81036
was published
Aug 26, 2026
Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success...
Low
Unreviewed
CVE-2026-80200
was published
Aug 26, 2026
Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically...
High
Unreviewed
CVE-2026-79786
was published
Aug 25, 2026
Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in...
High
Unreviewed
CVE-2026-79662
was published
Aug 25, 2026
A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function...
Low
Unreviewed
CVE-2026-78145
was published
Aug 24, 2026
ProTip!
Advisories are also available from the
GraphQL API