GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
6,971 advisories
Filter by severity
Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
High
CVE-2026-55851
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jul 22, 2026
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
High
CVE-2026-55833
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Netty SPDY SETTINGS frame count materializes unbounded settings map
High
CVE-2026-55831
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
Moderate
CVE-2026-59889
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jul 21, 2026
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
High
GHSA-r7wm-3cxj-wff9
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Jul 21, 2026
jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
Moderate
GHSA-mhm7-754m-9p8w
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jul 21, 2026
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
Moderate
CVE-2026-59888
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jul 21, 2026
PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms
High
CVE-2026-54291
was published
for
org.postgresql:postgresql
(Maven)
Jul 21, 2026
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
High
CVE-2026-11400
was published
for
software.amazon.jdbc:aws-advanced-jdbc-wrapper
(Maven)
Jul 17, 2026
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
High
GHSA-x8mg-6r4p-87pf
was published
for
com.arcadedb:arcadedb-server
(Maven)
Jul 16, 2026
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
High
GHSA-vwjc-v7x7-cm6g
was published
for
com.arcadedb:arcadedb-engine
(Maven)
Jul 16, 2026
ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
High
GHSA-x9f9-r4m8-9xc2
was published
for
com.arcadedb:arcadedb-engine
(Maven)
Jul 16, 2026
ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
High
GHSA-48qw-824m-86pr
was published
for
com.arcadedb:arcadedb-server
(Maven)
Jul 16, 2026
ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)
High
CVE-2026-54076
was published
for
com.arcadedb:arcadedb-engine
(Maven)
Jul 16, 2026
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
High
CVE-2026-54077
was published
for
com.arcadedb:arcadedb-engine
(Maven)
Jul 16, 2026
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50270
was published
for
com.datadoghq:dd-java-agent
(Maven)
Jul 15, 2026
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
High
CVE-2026-44891
was published
for
io.netty:netty-codec-stomp
(Maven)
Jul 14, 2026
Apollo ConfigService access key authentication bypass via raw config file appId parsing
High
CVE-2026-59955
was published
for
com.ctrip.framework.apollo:apollo
(Maven)
Jul 13, 2026
Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
High
CVE-2026-59954
was published
for
com.ctrip.framework.apollo:apollo
(Maven)
Jul 13, 2026
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
Moderate
CVE-2025-32781
was published
for
com.ctrip.framework.apollo:apollo
(Maven)
Jul 13, 2026
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization
Moderate
CVE-2026-49844
was published
for
org.apache.logging.log4j:log4j-api
(Maven)
Jul 11, 2026
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
High
CVE-2026-49485
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
(Maven)
Jul 9, 2026
Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers
Moderate
GHSA-q6gh-6v2r-hjv3
was published
for
io.micronaut:micronaut-http-client
(Maven)
Jul 9, 2026
Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS
High
GHSA-387m-935m-c4vw
was published
for
io.micronaut:micronaut-http-client
(Maven)
Jul 9, 2026
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
High
CVE-2026-49464
was published
for
nl.nl-portal:taak
(Maven)
Jul 8, 2026
ProTip!
Advisories are also available from the
GraphQL API