GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
59 advisories
Filter by severity
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
Moderate
CVE-2026-71311
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
undici vulnerable to CRLF Injection via blob-like body 'type' property
Moderate
CVE-2026-15157
was published
for
undici
(npm)
Aug 3, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Moderate
CVE-2026-49756
was published
for
req
(Erlang)
Jul 29, 2026
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
Moderate
CVE-2026-59921
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Netty: STOMP CONNECT Frame Header Injection in Netty
Moderate
CVE-2026-59920
was published
for
io.netty:netty-codec-stomp
(Maven)
Jul 22, 2026
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
Moderate
CVE-2026-59919
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jul 22, 2026
net-imap vulnerable to command Injection via unvalidated Symbol inputs
Moderate
CVE-2026-42258
was published
for
net-imap
(RubyGems)
May 4, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
Moderate
CVE-2026-49214
was published
for
guzzlehttp/psr7
(Composer)
Jun 11, 2026
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
Moderate
CVE-2026-53533
was published
for
aiosmtplib
(pip)
Jul 7, 2026
Net::IMAP: Command Injection via ID command argument
Moderate
CVE-2026-47242
was published
for
net-imap
(RubyGems)
Jun 9, 2026
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
Moderate
CVE-2026-47240
was published
for
net-imap
(RubyGems)
Jun 9, 2026
Hackney has CRLF / header injection in WebSocket upgrade request
Moderate
CVE-2026-47072
was published
for
hackney
(Erlang)
Jun 26, 2026
Hackney has CR/LF injection in query parameter
Moderate
CVE-2026-47075
was published
for
hackney
(Erlang)
Jun 26, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
Moderate
CVE-2026-55766
was published
for
guzzlehttp/psr7
(Composer)
Jun 19, 2026
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
Moderate
CVE-2026-9679
was published
for
undici
(npm)
Jun 19, 2026
Kirby: Request header injection in `Http\Remote`
Moderate
CVE-2026-50188
was published
for
getkirby/cms
(Composer)
Jun 18, 2026
net-imap vulnerable to command Injection via "raw" arguments to multiple commands
Moderate
CVE-2026-42257
was published
for
net-imap
(RubyGems)
May 4, 2026
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
Moderate
GHSA-268h-hp4c-crq3
was published
for
nodemailer
(npm)
Jun 15, 2026
SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator
Moderate
CVE-2026-28970
was published
for
github.com/apple/swift-nio
(Swift)
Jun 12, 2026
Netty Redis Codec Encoder has a CRLF Injection Issue
Moderate
CVE-2026-42586
was published
for
io.netty:netty-codec-redis
(Maven)
May 7, 2026
eventsource-encoder vulnerable to SSE event injection via unsanitized `event` and `id` fields
Moderate
CVE-2026-44214
was published
for
eventsource-encoder
(npm)
May 8, 2026
ninenines cowlib: Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability allows SSE event splitting and injection via unvalidated field values
Moderate
CVE-2026-43968
was published
for
cowlib
(Erlang)
May 11, 2026
Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names
Moderate
CVE-2026-45070
was published
for
symfony/mime
(Composer)
May 27, 2026
sse-channel: SSE Injection via unsanitized event fields
Moderate
CVE-2026-44217
was published
for
sse-channel
(npm)
May 5, 2026
Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values
Moderate
CVE-2026-26962
was published
for
rack
(RubyGems)
Apr 2, 2026
ProTip!
Advisories are also available from the
GraphQL API