GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,078 advisories
Filter by severity
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
High
CVE-2026-54727
was published
for
proot-distro
(pip)
Jul 29, 2026
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
High
CVE-2026-54504
was published
for
@andrea9293/mcp-documentation-server
(npm)
Jul 15, 2026
ViewComponent: Reused Component Instances Retain Stale Render Context
Moderate
CVE-2026-54497
was published
for
view_component
(RubyGems)
Jul 15, 2026
open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters
Moderate
CVE-2026-54495
was published
for
github.com/open-feature/open-feature-operator
(Go)
Jul 15, 2026
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2...
High
Unreviewed
CVE-2026-59835
was published
Jul 14, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
Moderate
CVE-2026-50202
was published
for
Steeltoe.Security.Authentication.CloudFoundryBase
(NuGet)
Jul 2, 2026
OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
Moderate
GHSA-6c4r-g249-wv3c
was published
for
openclaw
(npm)
Jul 2, 2026
PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger...
High
Unreviewed
CVE-2026-56077
was published
Jun 19, 2026
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
High
CVE-2026-57144
was published
for
praisonai
(pip)
Jun 18, 2026
OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session...
Low
Unreviewed
CVE-2026-53826
was published
Jun 13, 2026
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
High
CVE-2026-54096
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
Moderate
CVE-2026-48096
was published
for
github.com/openfga/openfga
(Go)
Jun 11, 2026
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author...
Critical
Unreviewed
CVE-2026-42535
was published
Jun 8, 2026
Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local...
High
Unreviewed
CVE-2025-15653
was published
Jun 3, 2026
Ironic Standalone Operator's prometheus metrics exporter bound to all interfaces
Moderate
GHSA-7cwm-fpfh-rrch
was published
for
github.com/metal3-io/ironic-standalone-operator
(Go)
May 29, 2026
NodeVM observability builtins leak host process and HTTP request data
Moderate
CVE-2026-47141
was published
for
vm2
(npm)
May 29, 2026
Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
High
CVE-2026-45077
was published
for
symfony/monolog-bridge
(Composer)
May 27, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
Moderate
CVE-2026-46430
was published
for
github.com/xyproto/algernon
(Go)
May 20, 2026
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This...
High
Unreviewed
CVE-2026-8958
was published
May 19, 2026
TYPO3 ke_search path traversal from arbitrary table configuration input
Moderate
CVE-2026-46723
was published
for
tpwd/ke_search
(Composer)
May 19, 2026
vm2 Has a Sandbox Breakout Using Async Generator
Critical
CVE-2026-45411
was published
for
vm2
(npm)
May 14, 2026
Vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program...
Low
Unreviewed
CVE-2026-34095
was published
May 11, 2026
Vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program...
Low
Unreviewed
CVE-2026-34094
was published
May 11, 2026
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
High
CVE-2026-44338
was published
for
PraisonAI
(pip)
May 11, 2026
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
High
CVE-2026-44552
was published
for
open-webui
(pip)
May 8, 2026
ProTip!
Advisories are also available from the
GraphQL API