GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,105 advisories
Filter by severity
A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when...
Moderate
Unreviewed
CVE-2026-18207
was published
Jul 29, 2026
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
Moderate
CVE-2026-49446
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache...
Moderate
Unreviewed
CVE-2026-61487
was published
Jul 28, 2026
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
High
CVE-2026-43983
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
An authorization issue was addressed with improved state management. This issue is fixed in iOS...
Moderate
Unreviewed
CVE-2026-64743
was published
Jul 27, 2026
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and...
Moderate
Unreviewed
CVE-2026-64711
was published
Jul 27, 2026
An authorization issue was addressed with improved state management. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-43775
was published
Jul 27, 2026
An authorization issue was addressed with improved state management. This issue is fixed in...
Moderate
Unreviewed
CVE-2026-43792
was published
Jul 27, 2026
A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is...
Low
Unreviewed
CVE-2026-17531
was published
Jul 27, 2026
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this...
Low
Unreviewed
CVE-2026-17530
was published
Jul 27, 2026
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown...
Low
Unreviewed
CVE-2026-17529
was published
Jul 27, 2026
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
GHSA-p279-2cqp-84jg
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
High
GHSA-pvcr-8mvp-w8qr
was published
for
@budibase/server
(npm)
Jul 24, 2026
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information...
Critical
Unreviewed
CVE-2026-62835
was published
Jul 24, 2026
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Low
CVE-2026-59226
was published
for
open-webui
(pip)
Jul 24, 2026
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate...
Critical
Unreviewed
CVE-2026-56160
was published
Jul 24, 2026
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Critical
GHSA-8fpg-xm3f-6cx3
was published
for
next-auth
(npm)
Jul 23, 2026
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
High
CVE-2026-64642
was published
for
next
(npm)
Jul 22, 2026
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component:...
Moderate
Unreviewed
CVE-2026-62563
was published
Jul 22, 2026
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component:...
Moderate
Unreviewed
CVE-2026-62444
was published
Jul 22, 2026
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component:...
Moderate
Unreviewed
CVE-2026-60911
was published
Jul 22, 2026
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component:...
Moderate
Unreviewed
CVE-2026-60842
was published
Jul 22, 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Moderate
Unreviewed
CVE-2026-60152
was published
Jul 22, 2026
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
Moderate
Unreviewed
CVE-2026-47053
was published
Jul 22, 2026
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
High
CVE-2026-58424
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API