GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
34,666 advisories
Filter by severity
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77415
was published
for
jsonata
(npm)
Aug 21, 2026
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77414
was published
for
jsonata
(npm)
Aug 21, 2026
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
High
CVE-2026-68508
was published
for
hydra-core
(pip)
Aug 21, 2026
YOURLS has stored XSS in referrer statistics chart via crafted Referer header
High
CVE-2026-63135
was published
for
yourls/yourls
(Composer)
Aug 21, 2026
JSONata: Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77413
was published
for
jsonata
(npm)
Aug 21, 2026
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
High
CVE-2026-77354
was published
for
github.com/getkin/kin-openapi
(Go)
Aug 21, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Critical
CVE-2026-61539
was published
for
xinference
(pip)
Aug 21, 2026
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
Critical
CVE-2026-59989
was published
for
phalcon/cphalcon
(Composer)
Aug 21, 2026
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS
High
CVE-2026-76905
was published
for
github.com/getkin/kin-openapi
(Go)
Aug 21, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
High
CVE-2026-64679
was published
for
github.com/runatlantis/atlantis
(Go)
Aug 21, 2026
Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
High
CVE-2026-63421
was published
for
@keystone-6/core
(npm)
Aug 21, 2026
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
High
CVE-2026-61824
was published
for
defuddle
(npm)
Aug 21, 2026
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
Critical
CVE-2026-76904
was published
for
org.geotools.jdbc:gt-jdbc-postgis
(Maven)
Aug 21, 2026
Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin
Moderate
GHSA-8hgv-xc77-jmcr
was published
for
getgrav/grav
(Composer)
Aug 21, 2026
Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
Moderate
CVE-2026-63466
was published
for
unleash-server
(npm)
Aug 21, 2026
Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
Moderate
CVE-2026-63004
was published
for
unleash-server
(npm)
Aug 21, 2026
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
High
CVE-2026-63462
was published
for
unleash-server
(npm)
Aug 21, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
Moderate
CVE-2026-67448
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
Moderate
CVE-2026-67447
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
Moderate
CVE-2026-55451
was published
for
gettext-converter
(npm)
Aug 20, 2026
Wagtail: Improper restriction handling on Page translation API endpoint
Moderate
GHSA-jm5p-837g-rv8g
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Improper permission handling when copying snippets
Moderate
GHSA-x5cx-w6p2-mxf2
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Improper restriction handling on descendant collections in Documents and Images API
Moderate
GHSA-c2xx-cjmh-9q8f
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Identification of documents by SHA1 hash
Low
GHSA-92hv-j533-69wc
was published
for
wagtail
(pip)
Aug 20, 2026
Winter: Reflected XSS through the search query parameter in the backend Table widget
Moderate
GHSA-hq84-x37p-j6q5
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API