GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
33,978 advisories
Filter by severity
Shescape: Home-directory disclosure in assignment context on Unix with Dash
Moderate
GHSA-q53c-4prm-w95q
was published
for
shescape
(npm)
Jul 24, 2026
Shescape: Shell injection via unescaped parentheses on Windows with CMD
Critical
GHSA-w4hw-qcx7-56pr
was published
for
shescape
(npm)
Jul 24, 2026
Shescape: Path disclosure on Unix with Zsh
Moderate
GHSA-6v4m-fw66-8r4x
was published
for
shescape
(npm)
Jul 24, 2026
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
High
CVE-2026-16584
was published
for
awslabs.aws-api-mcp-server
(pip)
Jul 24, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
Moderate
GHSA-86cx-wwf4-phq4
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
Moderate
GHSA-p6ph-3jx2-3337
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
High
GHSA-95cv-r8x4-vh75
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
High
GHSA-7ppr-r889-mcf2
was published
for
org.http4s:http4s-blaze-server_2.12
(Maven)
Jul 24, 2026
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
High
GHSA-46q4-43ph-c6fr
was published
for
org.http4s:blaze-http_2.12
(Maven)
Jul 24, 2026
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
High
GHSA-mhvj-jhpq-885v
was published
for
org.http4s:blaze-http_2.13
(Maven)
Jul 24, 2026
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
High
GHSA-cmwh-g2h8-c222
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
High
GHSA-h4hf-v6w5-897x
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
Critical
GHSA-f25v-x6vr-962g
was published
for
pheditor/pheditor
(Composer)
Jul 24, 2026
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
High
CVE-2026-14257
was published
for
brace-expansion
(npm)
Jul 24, 2026
swift-nio-http2: Missing CR/LF/NUL validation in header values
Moderate
CVE-2026-64785
was published
for
swift-nio-http2
(Swift)
Jul 24, 2026
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
Critical
GHSA-vh45-f885-3848
was published
for
sm-crypto
(npm)
Jul 24, 2026
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Moderate
GHSA-v6w6-358x-2433
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
High
GHSA-47w6-gwp4-w6vc
was published
for
vantage6
(pip)
Jul 24, 2026
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
Low
GHSA-2625-rw7m-5q5x
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
Moderate
GHSA-qqc3-94qv-7fw3
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
Moderate
GHSA-f45q-w629-wr25
was published
for
hubuum_client
(Rust)
Jul 24, 2026
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
High
GHSA-26gq-p25f-99cp
was published
for
github.com/fatedier/frp
(Go)
Jul 24, 2026
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
High
GHSA-g5vv-q72c-7j78
was published
for
@anephenix/hub
(npm)
Jul 24, 2026
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
Moderate
GHSA-c534-2w9c-x7fm
was published
for
github.com/zxh326/kite
(Go)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API