GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,135 advisories
Filter by severity
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
GHSA-pmwx-rm49-xv39
was published
for
activerecord-tenanted
(RubyGems)
Jul 29, 2026
Pagy I18n locale option is not validated before being used in a file path
Moderate
CVE-2026-54659
was published
for
pagy
(RubyGems)
Jul 28, 2026
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
High
CVE-2026-54603
was published
for
oauth2
(RubyGems)
Jul 28, 2026
OAuth: Cross-origin token-request redirects can expose signed request metadata
High
CVE-2026-54605
was published
for
oauth
(RubyGems)
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
CVE-2026-54620
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
CVE-2026-54619
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
Moderate
GHSA-53g2-mvcc-q9x3
was published
for
action_text-trix
(RubyGems)
Jul 24, 2026
Ruby json: JSON generator heap buffer overflow when streaming to an IO
Low
CVE-2026-54696
was published
for
json
(RubyGems)
Jul 23, 2026
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Moderate
GHSA-cj75-f6xr-r4g7
was published
for
rails-html-sanitizer
(RubyGems)
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Low
GHSA-5qhf-9phg-95m2
was published
for
loofah
(RubyGems)
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
Moderate
GHSA-9wjq-cp2p-hrgf
was published
for
loofah
(RubyGems)
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
CVE-2026-61666
was published
for
websocket-driver
(RubyGems)
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Low
GHSA-8whx-365g-h9vv
was published
for
loofah
(RubyGems)
Jul 21, 2026
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50276
was published
for
datadog
(RubyGems)
Jul 15, 2026
ViewComponent: Reused Component Instances Retain Stale Render Context
Moderate
CVE-2026-54497
was published
for
view_component
(RubyGems)
Jul 15, 2026
ViewComponent: around_render HTML-Safety Bypass
High
CVE-2026-54498
was published
for
view_component
(RubyGems)
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Moderate
CVE-2026-54465
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Moderate
CVE-2026-54464
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Moderate
CVE-2026-54463
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
Decidim: Push subscriptions can be abused for server-side requests
Moderate
CVE-2026-45573
was published
for
decidim-core
(RubyGems)
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
Moderate
CVE-2026-45572
was published
for
decidim-core
(RubyGems)
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
Moderate
CVE-2026-45415
was published
for
decidim-verifications
(RubyGems)
Jul 13, 2026
Decidim: JWT-backed authentication can be replayed across organizations
High
CVE-2026-45414
was published
for
decidim
(RubyGems)
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
High
CVE-2026-45378
was published
for
decidim-verifications
(RubyGems)
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
Moderate
CVE-2026-45377
was published
for
decidim-core
(RubyGems)
Jul 13, 2026
ProTip!
Advisories are also available from the
GraphQL API