GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,351 advisories
Filter by severity
Budibase: SQL Injection via `multipleStatements: true`
Critical
CVE-2026-73300
was published
for
@budibase/server
(npm)
Jul 24, 2026
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Critical
GHSA-w28w-gp39-m4p6
was published
for
@prompty/core
(npm)
Jul 24, 2026
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
Critical
CVE-2026-73649
was published
for
velocityjs
(npm)
Jul 24, 2026
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
Critical
CVE-2026-59940
was published
for
seroval
(npm)
Jul 24, 2026
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
Critical
GHSA-rjg6-39jm-rgg4
was published
for
@better-auth/scim
(npm)
Jul 24, 2026
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Critical
CVE-2026-73421
was published
for
next-auth
(npm)
Jul 23, 2026
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Critical
CVE-2026-73420
was published
for
@auth/core
(npm)
Jul 23, 2026
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
Critical
CVE-2026-73653
was published
for
@vitest/browser
(npm)
Jul 21, 2026
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
Critical
CVE-2026-59891
was published
for
@sigstore/oci
(npm)
Jul 21, 2026
node-tar: Decompression/parse DoS via unlimited input
Critical
CVE-2026-59873
was published
for
tar
(npm)
Jul 20, 2026
websocket-driver: Message corruption via abuse of protocol length headers
Critical
CVE-2026-54466
was published
for
websocket-driver
(npm)
Jul 15, 2026
TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution
Critical
GHSA-9hc2-hjx8-q6pv
was published
for
tidgi
(npm)
Jul 14, 2026
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
Critical
CVE-2026-54052
was published
for
n8n-mcp
(npm)
Jul 14, 2026
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
Critical
CVE-2026-53513
was published
for
@better-auth/sso
(npm)
Jul 7, 2026
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
Critical
CVE-2026-53512
was published
for
better-auth
(npm)
Jul 7, 2026
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
Critical
CVE-2026-55500
was published
for
9router
(npm)
Jul 6, 2026
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
Critical
GHSA-vjc7-jrh9-9j86
was published
for
9router
(npm)
Jul 6, 2026
Decompress: Archive extraction can create files and links outside of the target directory
Critical
CVE-2026-53486
was published
for
@xhmikosr/decompress
(npm)
Jul 6, 2026
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
Critical
CVE-2026-49352
was published
for
9router
(npm)
Jul 2, 2026
9router: Missing Authorization and OS Command Injection
Critical
CVE-2026-59800
was published
for
9router
(npm)
Jul 2, 2026
OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
Critical
GHSA-w4v6-g3wm-w36c
was published
for
openclaw
(npm)
Jul 2, 2026
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
Critical
CVE-2026-53943
was published
for
ghost
(npm)
Jul 1, 2026
deepstream is vulnerable to prototype pollution
Critical
CVE-2026-49252
was published
for
@deepstream/server
(npm)
Jun 26, 2026
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
Critical
CVE-2026-48797
was published
for
@mcptoolshop/backpropagate
(npm)
Jun 26, 2026
i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string
Critical
CVE-2026-48713
was published
for
i18next-fs-backend
(npm)
Jun 25, 2026
ProTip!
Advisories are also available from the
GraphQL API