GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
3,342 advisories
Filter by severity
OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`
Moderate
CVE-2026-44202
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Jun 22, 2026
http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments
Moderate
GHSA-c7jm-38gq-h67h
was published
for
org.http4k:http4k-security-digest
(Maven)
Jun 19, 2026
http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default
Moderate
GHSA-pr33-38xx-6r26
was published
for
org.http4k:http4k-core
(Maven)
Jun 19, 2026
http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`
Moderate
GHSA-jrpc-7vxp-69p6
was published
for
org.http4k:http4k-core
(Maven)
Jun 19, 2026
Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering
Moderate
CVE-2026-55847
was published
for
io.qameta.allure:allure-generator
(Maven)
Jun 19, 2026
Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read
Moderate
CVE-2026-55846
was published
for
io.qameta.allure:allure-commandline
(Maven)
Jun 19, 2026
NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
Moderate
CVE-2026-55414
was published
for
nl.nl-portal:form
(Maven)
Jun 19, 2026
Armeria: External Control of File Name or Path in xDS SDS DataSource
Moderate
CVE-2026-11752
was published
for
com.linecorp.armeria:armeria-xds
(Maven)
Jun 18, 2026
NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
Moderate
CVE-2026-54683
was published
for
nl.nl-portal:documenten-api
(Maven)
Jun 18, 2026
Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
Moderate
CVE-2026-55226
was published
for
io.strimzi:strimzi
(Maven)
Jun 18, 2026
Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
Moderate
CVE-2026-47340
was published
for
org.apache.dolphinscheduler:dolphinscheduler-api
(Maven)
Jun 17, 2026
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
Moderate
CVE-2026-42357
was published
for
org.apache.dolphinscheduler:dolphinscheduler-api
(Maven)
Jun 17, 2026
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
Moderate
CVE-2026-41280
was published
for
org.apache.dolphinscheduler:dolphinscheduler-api
(Maven)
Jun 17, 2026
Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
Moderate
CVE-2026-50560
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 15, 2026
Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
Moderate
CVE-2026-50020
was published
for
io.netty:netty-codec-http
(Maven)
Jun 15, 2026
Netty: QUIC stateless reset token material exposed through header-visible connection IDs
Moderate
CVE-2026-50009
was published
for
io.netty:netty-codec-classes-quic
(Maven)
Jun 15, 2026
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing
Moderate
CVE-2026-54697
was published
for
org.connectbot.sshlib:sshlib
(Maven)
Jun 12, 2026
ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation
Moderate
CVE-2026-54700
was published
for
org.connectbot.sshlib:sshlib
(Maven)
Jun 12, 2026
GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
Moderate
CVE-2025-58175
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 12, 2026
Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
Moderate
CVE-2026-50634
was published
for
org.apache.cxf:cxf-rt-rs-security-jose-jaxrs
(Maven)
Jun 12, 2026
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService
Moderate
CVE-2026-50623
was published
for
org.apache.cxf:cxf-rt-rs-security-oauth2
(Maven)
Jun 12, 2026
Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection
Moderate
CVE-2026-50630
was published
for
org.apache.cxf:cxf-rt-rs-security-oauth2
(Maven)
Jun 12, 2026
Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks
Moderate
CVE-2026-11986
was published
for
org.keycloak:keycloak-rest-admin-ui-ext
(Maven)
Jun 11, 2026
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
Moderate
CVE-2026-48043
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 11, 2026
netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
Moderate
CVE-2026-48040
was published
for
io.netty.incubator:netty-incubator-codec-ohttp-hpke-native-boringssl
(Maven)
Jun 11, 2026
ProTip!
Advisories are also available from the
GraphQL API