GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
59 advisories
Filter by severity
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
High
CVE-2026-54511
was published
for
@logtape/syslog
(npm)
Aug 26, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated...
High
Unreviewed
CVE-2026-70615
was published
Aug 5, 2026
An unauthenticated remote attacker can inject malicious input into the ModbusServer application...
High
Unreviewed
CVE-2026-44092
was published
Jul 30, 2026
Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution...
High
Unreviewed
CVE-2026-12357
was published
Jul 29, 2026
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs...
High
Unreviewed
CVE-2026-16313
was published
Jul 28, 2026
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST...
High
Unreviewed
CVE-2026-57281
was published
Jun 24, 2026
skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery
High
GHSA-74p7-6h78-gw8p
was published
for
skillctl
(Rust)
Jun 22, 2026
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
High
CVE-2026-55603
was published
for
http-proxy-middleware
(npm)
Jun 18, 2026
Laravel Framework: CRLF injection in default email rule
High
GHSA-5vg9-5847-vvmq
was published
for
laravel/framework
(Composer)
Jun 17, 2026
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
High
GHSA-7cx2-g3h9-382p
was published
for
crawl4ai
(pip)
Jun 16, 2026
form-data: CRLF injection in form-data via unescaped multipart field names and filenames
High
CVE-2026-12143
was published
for
form-data
(npm)
Jun 15, 2026
Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier
High
CVE-2026-50629
was published
for
org.apache.cxf:cxf-rt-rs-security-oauth2
(Maven)
Jun 12, 2026
Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric...
High
Unreviewed
CVE-2026-50637
was published
Jun 10, 2026
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output...
High
Unreviewed
CVE-2026-50292
was published
Jun 4, 2026
Etsy::StatsD versions through 1.002002 for Perl allow metric injections.
The metric names and...
High
Unreviewed
CVE-2026-46741
was published
Jun 4, 2026
Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
High
CVE-2026-45067
was published
for
symfony/mime
(Composer)
May 27, 2026
Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections.
The values from...
High
Unreviewed
CVE-2026-8788
was published
May 18, 2026
Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections.
The metric names and...
High
Unreviewed
CVE-2026-46720
was published
May 17, 2026
Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint...
High
Unreviewed
CVE-2026-32993
was published
May 14, 2026
Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM...
High
Unreviewed
CVE-2026-5140
was published
Apr 29, 2026
PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes
High
GHSA-mh6w-vxff-9wqp
was published
for
phpunit/phpunit
(Composer)
Apr 22, 2026
PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes
High
CVE-2026-41570
was published
for
phpunit/phpunit
(Composer)
Apr 18, 2026
MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing...
High
Unreviewed
CVE-2026-6351
was published
Apr 16, 2026
Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()
High
CVE-2026-41230
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
ProTip!
Advisories are also available from the
GraphQL API