GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
611 advisories
Filter by severity
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
Moderate
CVE-2026-49446
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS...
Moderate
Unreviewed
CVE-2026-28849
was published
Jul 27, 2026
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-28900
was published
Jul 27, 2026
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
High
CVE-2026-59224
was published
for
open-webui
(pip)
Jul 24, 2026
A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass...
Moderate
Unreviewed
CVE-2026-11922
was published
Jul 24, 2026
GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.
Moderate
Unreviewed
CVE-2026-64875
was published
Jul 23, 2026
IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy....
High
Unreviewed
CVE-2026-64797
was published
Jul 22, 2026
IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass...
High
Unreviewed
CVE-2026-63683
was published
Jul 22, 2026
In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy...
Low
Unreviewed
CVE-2026-54478
was published
Jul 22, 2026
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive...
Critical
Unreviewed
CVE-2026-50755
was published
Jul 21, 2026
Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
High
Unreviewed
CVE-2026-16404
was published
Jul 21, 2026
Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor...
High
Unreviewed
CVE-2026-3183
was published
Jul 21, 2026
A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet ...
Moderate
Unreviewed
CVE-2026-15812
was published
Jul 21, 2026
OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the...
Low
Unreviewed
CVE-2026-62224
was published
Jul 17, 2026
A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event...
High
Unreviewed
CVE-2026-12382
was published
Jul 15, 2026
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
High
CVE-2026-50141
was published
for
go.woodpecker-ci.org/woodpecker/v3
(Go)
Jul 14, 2026
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube...
Moderate
Unreviewed
CVE-2026-62644
was published
Jul 14, 2026
PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing...
Moderate
Unreviewed
CVE-2026-61428
was published
Jul 11, 2026
File Browser: Authentication Bypass via Proxy Auth Header Forgery
Critical
CVE-2026-54089
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 10, 2026
Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module...
Low
Unreviewed
CVE-2026-8651
was published
Jul 8, 2026
n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks...
Moderate
Unreviewed
CVE-2026-56360
was published
Jul 8, 2026
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
High
CVE-2026-55501
was published
for
9router
(npm)
Jul 6, 2026
Authentication Bypass by Spoofing vulnerability in Apache IoTDB.
Certain Thrift RPC query...
Critical
Unreviewed
CVE-2026-24013
was published
Jul 6, 2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Moderate
Unreviewed
CVE-2026-45489
was published
Jul 3, 2026
9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
High
CVE-2026-49353
was published
for
9router
(npm)
Jul 2, 2026
ProTip!
Advisories are also available from the
GraphQL API