GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
33,978 advisories
Filter by severity
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
High
CVE-2026-54690
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
High
CVE-2026-55415
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
High
CVE-2026-54621
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
High
CVE-2026-54655
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
Low
CVE-2026-55403
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
High
CVE-2026-54691
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
High
CVE-2026-55390
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
High
CVE-2026-32203
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 28, 2026
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
Moderate
CVE-2026-52888
was published
for
@nocobase/plugin-collection-sql
(npm)
Jul 28, 2026
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
Moderate
CVE-2026-49446
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Moderate
CVE-2026-49447
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
Low
CVE-2026-50568
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory
High
CVE-2026-50567
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
Moderate
CVE-2026-50569
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
High
CVE-2026-50570
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
pytonapi has a Webhook Custom Path Authentication Bypass
High
CVE-2026-54635
was published
for
pytonapi
(pip)
Jul 28, 2026
SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)
High
CVE-2026-54632
was published
for
SIPSorcery
(NuGet)
Jul 28, 2026
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
Critical
CVE-2026-54588
was published
for
poweradmin/poweradmin
(Composer)
Jul 28, 2026
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
High
CVE-2026-54603
was published
for
oauth2
(RubyGems)
Jul 28, 2026
OAuth: Cross-origin token-request redirects can expose signed request metadata
High
CVE-2026-54605
was published
for
oauth
(RubyGems)
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
CVE-2026-54620
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
CVE-2026-54619
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
Moderate
CVE-2026-54332
was published
for
github.com/gopacket/gopacket
(Go)
Jul 28, 2026
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
Moderate
CVE-2026-54345
was published
for
github.com/gopacket/gopacket
(Go)
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API