GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,135 advisories
Filter by severity
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
GHSA-pmwx-rm49-xv39
was published
for
activerecord-tenanted
(RubyGems)
Jul 29, 2026
Pagy I18n locale option is not validated before being used in a file path
Moderate
CVE-2026-54659
was published
for
pagy
(RubyGems)
Jul 28, 2026
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
High
CVE-2026-54603
was published
for
oauth2
(RubyGems)
Jul 28, 2026
OAuth: Cross-origin token-request redirects can expose signed request metadata
High
CVE-2026-54605
was published
for
oauth
(RubyGems)
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
CVE-2026-54620
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
CVE-2026-54619
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
Moderate
GHSA-53g2-mvcc-q9x3
was published
for
action_text-trix
(RubyGems)
Jul 24, 2026
Ruby json: JSON generator heap buffer overflow when streaming to an IO
Low
CVE-2026-54696
was published
for
json
(RubyGems)
Jul 23, 2026
net-imap vulnerable to command Injection via unvalidated Symbol inputs
Moderate
CVE-2026-42258
was published
for
net-imap
(RubyGems)
May 4, 2026
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Moderate
GHSA-cj75-f6xr-r4g7
was published
for
rails-html-sanitizer
(RubyGems)
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Low
GHSA-5qhf-9phg-95m2
was published
for
loofah
(RubyGems)
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
Moderate
GHSA-9wjq-cp2p-hrgf
was published
for
loofah
(RubyGems)
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
CVE-2026-61666
was published
for
websocket-driver
(RubyGems)
Jul 21, 2026
Excon does not redact additional sensitive/risky headers when following redirects
Moderate
CVE-2026-54171
was published
for
excon
(RubyGems)
Jul 10, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Low
GHSA-8whx-365g-h9vv
was published
for
loofah
(RubyGems)
Jul 21, 2026
Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
Low
CVE-2026-54905
was published
for
concurrent-ruby
(RubyGems)
Jun 19, 2026
katello: missing repository authorization in content_uploads exposes cross-product content existence
Moderate
CVE-2026-12515
was published
for
katello
(RubyGems)
Jun 17, 2026
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Critical
CVE-2026-55518
was published
for
avo
(RubyGems)
Jun 17, 2026
decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embeds
Moderate
CVE-2024-45594
was published
for
decidim-meetings
(RubyGems)
Nov 13, 2024
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50276
was published
for
datadog
(RubyGems)
Jul 15, 2026
ViewComponent: Reused Component Instances Retain Stale Render Context
Moderate
CVE-2026-54497
was published
for
view_component
(RubyGems)
Jul 15, 2026
ViewComponent: around_render HTML-Safety Bypass
High
CVE-2026-54498
was published
for
view_component
(RubyGems)
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Moderate
CVE-2026-54465
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Moderate
CVE-2026-54464
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Moderate
CVE-2026-54463
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
ProTip!
Advisories are also available from the
GraphQL API