GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
33,978 advisories
Filter by severity
GitHub CLI has an incorrect authorization header in API requests to TUF repository mirrors via `gh attestation`, `gh release verify`, and `gh release verify-asset` commands
High
CVE-2026-48501
was published
for
github.com/cli/cli/v2
(Go)
May 29, 2026
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
Moderate
CVE-2026-41715
was published
for
io.projectreactor.netty:reactor-netty
(Maven)
Jun 9, 2026
Spring LDAP has Authentication Bypass with Empty Password
High
CVE-2026-41720
was published
for
org.springframework.ldap:spring-ldap-core
(Maven)
Jun 9, 2026
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
Moderate
CVE-2026-41710
was published
for
org.springframework.retry:spring-retry
(Maven)
Jun 9, 2026
Spring Framework Predictable Session ID in WebSocket Module
Moderate
CVE-2026-41838
was published
for
org.springframework:spring-websocket
(Maven)
Jun 9, 2026
Spring HATEOAS heap exhaustion through unbounded internal caching
High
CVE-2026-41007
was published
for
org.springframework.hateoas:spring-hateoas
(Maven)
Jun 9, 2026
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
High
CVE-2026-41006
was published
for
org.springframework.hateoas:spring-hateoas
(Maven)
Jun 9, 2026
mathlive's Lack of Escaping of HTML allows for XSS
Moderate
CVE-2026-54705
was published
for
mathlive
(npm)
Jul 29, 2026
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Moderate
CVE-2026-54704
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Moderate
CVE-2026-54712
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
GHSA-pmwx-rm49-xv39
was published
for
activerecord-tenanted
(RubyGems)
Jul 29, 2026
netfoil: Incorrect block responses could lead to localhost traffic
High
GHSA-xvg2-cgv6-6h7v
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Jul 29, 2026
Logging operator has Fluentd configuration injection that allows remote code execution
Critical
CVE-2026-54680
was published
for
github.com/kube-logging/logging-operator
(Go)
Jul 29, 2026
ZITADEL Users Can Self-Verify Email/Phone via API
High
CVE-2026-54693
was published
for
github.com/zitadel/zitadel
(Go)
Jul 29, 2026
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
High
CVE-2026-54727
was published
for
proot-distro
(pip)
Jul 29, 2026
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
High
CVE-2026-54574
was published
for
proot-distro
(pip)
Jul 29, 2026
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
Low
CVE-2026-52838
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
Low
CVE-2026-52841
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Moderate
CVE-2026-52837
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Low
CVE-2026-52839
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Low
CVE-2026-52840
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
High
CVE-2026-55651
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
Moderate
GHSA-wchh-9x6h-7f6p
was published
for
matrix-commander
(pip)
Jul 29, 2026
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
High
CVE-2026-11393
was published
for
@aws/agentcore
(npm)
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
Critical
CVE-2026-54735
was published
for
github.com/prebid/prebid-server
(Go)
Jul 29, 2026
ProTip!
Advisories are also available from the
GraphQL API