GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
36 advisories
Filter by severity
Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
High
CVE-2026-75837
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
High
CVE-2026-81516
was published
for
Steeltoe.Discovery.Consul
(NuGet)
Sep 17, 2026
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
High
CVE-2026-81515
was published
for
Steeltoe.Discovery.Eureka
(NuGet)
Sep 17, 2026
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
Moderate
CVE-2026-75523
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Sep 17, 2026
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
Moderate
CVE-2026-85732
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
Moderate
CVE-2026-88016
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
High
CVE-2026-87995
was published
for
open-webui
(pip)
Sep 10, 2026
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
Moderate
CVE-2026-78679
was published
for
GitPython
(pip)
Sep 8, 2026
GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
Moderate
CVE-2026-78678
was published
for
GitPython
(pip)
Sep 8, 2026
pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph
High
CVE-2026-82392
was published
for
pnpm
(npm)
Sep 2, 2026
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
High
GHSA-8rr7-cvq3-gmfh
was published
for
league/commonmark
(Composer)
Sep 1, 2026
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
Critical
CVE-2026-55559
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
Critical
CVE-2026-55511
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
High
GHSA-fm29-4mq3-phg6
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
Moderate
CVE-2026-73974
was published
for
linuxfabrik-lib
(pip)
Aug 18, 2026
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
High
GHSA-pfvm-w89x-94jw
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
High
GHSA-jwjp-4649-v8jp
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
High
CVE-2026-76220
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
High
GHSA-jm78-9fvv-mhgr
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
High
CVE-2026-76218
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
High
CVE-2026-76219
was published
for
GitPython
(pip)
Aug 7, 2026
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
Moderate
CVE-2026-64663
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
High
CVE-2026-70486
was published
for
open-webui
(pip)
Aug 4, 2026
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
Moderate
GHSA-p538-c434-8v24
was published
for
GitPython
(pip)
Aug 3, 2026
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
High
CVE-2026-67424
was published
for
flyto-core
(pip)
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API