GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
96 advisories
Filter by severity
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
High
CVE-2026-54511
was published
for
@logtape/syslog
(npm)
Aug 26, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
Moderate
CVE-2026-71311
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
undici vulnerable to CRLF Injection via blob-like body 'type' property
Moderate
CVE-2026-15157
was published
for
undici
(npm)
Aug 3, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Moderate
CVE-2026-49756
was published
for
req
(Erlang)
Jul 29, 2026
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
Moderate
CVE-2026-59921
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Netty: STOMP CONNECT Frame Header Injection in Netty
Moderate
CVE-2026-59920
was published
for
io.netty:netty-codec-stomp
(Maven)
Jul 22, 2026
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
Moderate
CVE-2026-59919
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jul 22, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
CVE-2026-48596
was published
for
tesla
(Erlang)
Jul 10, 2026
mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`
Low
CVE-2026-48861
was published
for
mint
(Erlang)
Jul 9, 2026
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
Moderate
CVE-2026-53533
was published
for
aiosmtplib
(pip)
Jul 7, 2026
Hackney has CRLF / header injection in WebSocket upgrade request
Moderate
CVE-2026-47072
was published
for
hackney
(Erlang)
Jun 26, 2026
Hackney has CR/LF injection in query parameter
Moderate
CVE-2026-47075
was published
for
hackney
(Erlang)
Jun 26, 2026
Hackney has CRLF / header injection via unvalidated `domain` and `path` options
Low
CVE-2026-47069
was published
for
hackney
(Erlang)
Jun 26, 2026
skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery
High
GHSA-74p7-6h78-gw8p
was published
for
skillctl
(Rust)
Jun 22, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
Moderate
CVE-2026-55766
was published
for
guzzlehttp/psr7
(Composer)
Jun 19, 2026
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
Moderate
CVE-2026-9679
was published
for
undici
(npm)
Jun 19, 2026
Kirby: Request header injection in `Http\Remote`
Moderate
CVE-2026-50188
was published
for
getkirby/cms
(Composer)
Jun 18, 2026
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
High
CVE-2026-55603
was published
for
http-proxy-middleware
(npm)
Jun 18, 2026
Laravel Framework: CRLF injection in default email rule
High
GHSA-5vg9-5847-vvmq
was published
for
laravel/framework
(Composer)
Jun 17, 2026
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
High
GHSA-7cx2-g3h9-382p
was published
for
crawl4ai
(pip)
Jun 16, 2026
aiohttp: CRLF injection in multipart headers
Low
CVE-2026-50269
was published
for
aiohttp
(pip)
Jun 15, 2026
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
Moderate
GHSA-268h-hp4c-crq3
was published
for
nodemailer
(npm)
Jun 15, 2026
form-data: CRLF injection in form-data via unescaped multipart field names and filenames
High
CVE-2026-12143
was published
for
form-data
(npm)
Jun 15, 2026
SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator
Moderate
CVE-2026-28970
was published
for
github.com/apple/swift-nio
(Swift)
Jun 12, 2026
ProTip!
Advisories are also available from the
GraphQL API