GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
210 advisories
Filter by severity
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6...
Moderate
Unreviewed
CVE-2026-71572
was published
Aug 18, 2026
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 -...
Moderate
Unreviewed
CVE-2026-71573
was published
Aug 18, 2026
Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list...
Moderate
Unreviewed
CVE-2026-82661
was published
Aug 31, 2026
Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope...
Critical
Unreviewed
CVE-2026-82854
was published
Aug 31, 2026
Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport...
Moderate
Unreviewed
CVE-2026-82853
was published
Aug 31, 2026
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs...
High
Unreviewed
CVE-2026-16313
was published
Jul 28, 2026
Spring MVC applications using the functional web framework are vulnerable to stream corruption...
Critical
Unreviewed
CVE-2026-59313
was published
Aug 27, 2026
Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands...
Moderate
Unreviewed
CVE-2026-33606
was published
Aug 28, 2026
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent...
Critical
Unreviewed
CVE-2026-47890
was published
Aug 27, 2026
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST...
High
Unreviewed
CVE-2026-57281
was published
Jun 24, 2026
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF...
Critical
Unreviewed
CVE-2026-77550
was published
Aug 27, 2026
A malicious actor with access to the network and under certain conditions could exploit an...
Critical
Unreviewed
CVE-2026-77549
was published
Aug 27, 2026
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
High
CVE-2026-54511
was published
for
@logtape/syslog
(npm)
Aug 26, 2026
Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded...
Moderate
Unreviewed
CVE-2026-75922
was published
Aug 23, 2026
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit...
Moderate
Unreviewed
CVE-2026-75484
was published
Aug 20, 2026
Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier
High
CVE-2026-50629
was published
for
org.apache.cxf:cxf-rt-rs-security-oauth2
(Maven)
Jun 12, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices...
Moderate
Unreviewed
CVE-2026-16455
was published
Aug 13, 2026
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an...
Critical
Unreviewed
CVE-2026-72590
was published
Aug 10, 2026
An injection vulnerability was found in libvirt's virtual network driver. The network XML parser...
Low
Unreviewed
CVE-2026-61477
was published
Aug 7, 2026
A privilege escalation vulnerability exists in the HTTP authentication component in Archer...
Moderate
Unreviewed
CVE-2026-15429
was published
Jul 14, 2026
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header...
Moderate
Unreviewed
CVE-2026-0673
was published
Aug 6, 2026
boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated...
High
Unreviewed
CVE-2026-70615
was published
Aug 5, 2026
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
Moderate
CVE-2026-71311
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
undici vulnerable to CRLF Injection via blob-like body 'type' property
Moderate
CVE-2026-15157
was published
for
undici
(npm)
Aug 3, 2026
ProTip!
Advisories are also available from the
GraphQL API