GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
91 advisories
Filter by severity
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
Low
CVE-2026-42350
was published
for
github.com/akuity/kargo
(Go)
Aug 27, 2026
Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success...
Low
Unreviewed
CVE-2026-80200
was published
Aug 26, 2026
A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function...
Low
Unreviewed
CVE-2026-78145
was published
Aug 24, 2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene...
Low
Unreviewed
CVE-2026-66829
was published
Aug 6, 2026
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
Low
CVE-2026-59730
was published
for
@astrojs/node
(npm)
Jul 20, 2026
A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown...
Low
Unreviewed
CVE-2026-18721
was published
Aug 4, 2026
Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows...
Low
Unreviewed
CVE-2026-67350
was published
Jul 31, 2026
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
Low
CVE-2026-55403
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
hsweb-framework has an open redirect issue
Low
CVE-2026-11477
was published
for
org.hswebframework.web:hsweb-authorization-oauth2
(Maven)
Jun 8, 2026
Forwarding of confidentials headers to third parties in fluture-node
Low
CVE-2022-24719
was published
for
fluture-node
(npm)
Mar 1, 2022
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9...
Low
Unreviewed
CVE-2026-7364
was published
Jul 17, 2026
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login
Low
CVE-2026-48589
was published
for
org.apache.shiro:shiro-jakarta-ee
(Maven)
May 26, 2026
Waku has an Open Redirect via `unstable_redirect` Helper
Low
CVE-2026-49456
was published
for
waku
(npm)
Jul 8, 2026
A vulnerability was found in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to...
Low
Unreviewed
CVE-2026-14632
was published
Jul 4, 2026
Concourse login flow has an open redirect issue
Low
CVE-2026-49826
was published
for
github.com/concourse/concourse
(Go)
Jul 1, 2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The default...
Low
Unreviewed
CVE-2026-44915
was published
Jun 19, 2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The attacker...
Low
Unreviewed
CVE-2026-48895
was published
Jun 19, 2026
A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the...
Low
Unreviewed
CVE-2026-12804
was published
Jun 21, 2026
An URL Redirection to Untrusted Site vulnerabilities [CWE-601] in FortiOS 7.6.0 through 7.6.2, 7...
Low
Unreviewed
CVE-2025-47890
was published
Oct 14, 2025
A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function...
Low
Unreviewed
CVE-2026-11502
was published
Jun 8, 2026
Mayan EDMS has an Open Redirect through the /authentication/ file
Low
CVE-2025-14692
was published
for
mayan-edms
(pip)
Dec 15, 2025
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
Low
Unreviewed
CVE-2026-49380
was published
May 29, 2026
action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.
Low
Unreviewed
CVE-2026-48832
was published
May 26, 2026
Open redirect endpoint in Datasette
Low
CVE-2025-64481
was published
for
datasette
(pip)
Nov 6, 2025
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple...
Low
Unreviewed
CVE-2024-22308
was published
Jan 24, 2024
ProTip!
Advisories are also available from the
GraphQL API