GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
6,875 advisories
Filter by severity
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Moderate
CVE-2026-54704
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Moderate
CVE-2026-54712
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
High
CVE-2026-50559
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
Jul 29, 2026
veraPDF Parser DoS via PostScript Type 1 Font Programs
Moderate
CVE-2026-54081
was published
for
org.verapdf:parser
(Maven)
Jul 29, 2026
veraPDF Parser DoS via PostScript CMap Streams
Moderate
CVE-2026-54080
was published
for
org.verapdf:parser
(Maven)
Jul 29, 2026
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
Moderate
CVE-2026-54082
was published
for
org.verapdf:validation-model
(Maven)
Jul 29, 2026
veraPDF Validation XXE via Rich Text
High
CVE-2026-54078
was published
for
org.verapdf:validation-model
(Maven)
Jul 29, 2026
veraPDF Validation XXE via XFA
High
CVE-2026-54079
was published
for
org.verapdf:validation-model
(Maven)
Jul 29, 2026
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
High
CVE-2026-55771
was published
for
com.cedarpolicy:cedar-java
(Maven)
Jul 28, 2026
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
High
CVE-2026-43910
was published
for
io.appium:java-client
(Maven)
Jul 28, 2026
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
Moderate
CVE-2023-37465
was published
for
org.xwiki.contrib:discussions-server
(Maven)
Jul 27, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries
High
GHSA-fp43-vj7g-pg92
was published
for
org.omnifaces:omnifaces
(Maven)
Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
High
GHSA-7ppr-r889-mcf2
was published
for
org.http4s:http4s-blaze-server_2.12
(Maven)
Jul 24, 2026
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
High
GHSA-46q4-43ph-c6fr
was published
for
org.http4s:blaze-http_2.12
(Maven)
Jul 24, 2026
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
High
GHSA-mhvj-jhpq-885v
was published
for
org.http4s:blaze-http_2.13
(Maven)
Jul 24, 2026
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
GHSA-p279-2cqp-84jg
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Critical
GHSA-68r5-9hpg-7qw9
was published
for
org.openidentityplatform.opendj:opendj-dsml-servlet
(Maven)
Jul 24, 2026
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
Critical
CVE-2026-62379
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Jul 24, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
Moderate
CVE-2026-62280
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jul 24, 2026
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
Critical
CVE-2026-62263
was published
for
org.openidentityplatform.openam:openam-auth-webauthn
(Maven)
Jul 24, 2026
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
High
GHSA-v74w-7mr3-4qg3
was published
for
io.netty:netty-codec-xml
(Maven)
Jul 24, 2026
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
Moderate
GHSA-mfg7-5gfp-c4w3
was published
for
io.netty:netty-codec-dns
(Maven)
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
Low
GHSA-464c-974j-9xm6
was published
for
@aws-cdk/aws-codebuild
(Go)
Jul 24, 2026
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
Moderate
CVE-2026-59949
was published
for
at.yawk.lz4:lz4-java
(Maven)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API