GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
33,978 advisories
Filter by severity
mathlive's Lack of Escaping of HTML allows for XSS
Moderate
CVE-2026-54705
was published
for
mathlive
(npm)
Jul 29, 2026
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Moderate
CVE-2026-54704
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Moderate
CVE-2026-54712
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
GHSA-pmwx-rm49-xv39
was published
for
activerecord-tenanted
(RubyGems)
Jul 29, 2026
netfoil: Incorrect block responses could lead to localhost traffic
High
GHSA-xvg2-cgv6-6h7v
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Jul 29, 2026
Logging operator has Fluentd configuration injection that allows remote code execution
Critical
CVE-2026-54680
was published
for
github.com/kube-logging/logging-operator
(Go)
Jul 29, 2026
ZITADEL Users Can Self-Verify Email/Phone via API
High
CVE-2026-54693
was published
for
github.com/zitadel/zitadel
(Go)
Jul 29, 2026
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
High
CVE-2026-54727
was published
for
proot-distro
(pip)
Jul 29, 2026
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
High
CVE-2026-54574
was published
for
proot-distro
(pip)
Jul 29, 2026
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
Low
CVE-2026-52838
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
Low
CVE-2026-52841
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Moderate
CVE-2026-52837
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Low
CVE-2026-52839
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Low
CVE-2026-52840
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
High
CVE-2026-55651
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
Moderate
GHSA-wchh-9x6h-7f6p
was published
for
matrix-commander
(pip)
Jul 29, 2026
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
High
CVE-2026-11393
was published
for
@aws/agentcore
(npm)
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
Critical
CVE-2026-54735
was published
for
github.com/prebid/prebid-server
(Go)
Jul 29, 2026
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
High
CVE-2026-50559
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
Jul 29, 2026
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
Low
GHSA-pc2w-4mq8-32qw
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 29, 2026
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
Moderate
CVE-2026-50558
was published
for
penelope-shell-handler
(pip)
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Moderate
CVE-2026-49756
was published
for
req
(Erlang)
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
CVE-2026-49755
was published
for
req
(Erlang)
Jul 29, 2026
veraPDF Parser DoS via PostScript Type 1 Font Programs
Moderate
CVE-2026-54081
was published
for
org.verapdf:parser
(Maven)
Jul 29, 2026
veraPDF Parser DoS via PostScript CMap Streams
Moderate
CVE-2026-54080
was published
for
org.verapdf:parser
(Maven)
Jul 29, 2026
ProTip!
Advisories are also available from the
GraphQL API