GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
700 advisories
Filter by severity
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
High
CVE-2026-41006
was published
for
org.springframework.hateoas:spring-hateoas
(Maven)
Jun 9, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
Critical
CVE-2026-64863
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
goodoneuz/pay-uz: the /payment/api/editable/update endpoint overwrites existing PHP payment hook files
Critical
CVE-2026-31843
was published
for
goodoneuz/pay-uz
(Composer)
Apr 16, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
ImageMagick: Policy Bypass in script operation due to missing checks
Low
GHSA-vghg-5jrg-2398
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
Low
GHSA-whvh-wf3x-g77j
was published
for
jupyterlab
(pip)
Jul 22, 2026
Netty: Security Control Bypass via CORS Short-Circuit Failure
Moderate
CVE-2026-56746
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Moderate
CVE-2026-58429
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
High
CVE-2026-58422
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
High
CVE-2026-24451
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Repository Visibility Manipulation via Git Push Options
High
CVE-2026-58437
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
High
CVE-2026-58421
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`
Critical
CVE-2026-20896
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
Moderate
CVE-2026-58507
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
High
CVE-2026-50132
was published
for
@budibase/server
(npm)
Jun 22, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
High
CVE-2026-52810
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints
Moderate
CVE-2026-47279
was published
for
nocodb
(npm)
Jun 5, 2026
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Moderate
CVE-2026-54761
was published
for
github.com/traefik/traefik
(Go)
Jun 17, 2026
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
Moderate
CVE-2026-54015
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
High
CVE-2026-54012
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI: Forged chat-file link allows cross-user file read and deletion
High
CVE-2026-54010
was published
for
open-webui
(pip)
Jun 17, 2026
Caddy: Windows `file_server` path authorization bypass via encoded backslash
High
CVE-2026-52844
was published
for
github.com/caddyserver/caddy
(Go)
Jun 16, 2026
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
Moderate
CVE-2026-49411
was published
for
deno
(Rust)
Jun 16, 2026
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
High
CVE-2026-54305
was published
for
n8n
(npm)
Jun 16, 2026
ProTip!
Advisories are also available from the
GraphQL API