GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,573
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
715 advisories
Filter by severity
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
High
CVE-2026-53831
was published
for
openclaw
(npm)
Jul 2, 2026
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
Critical
CVE-2026-55536
was published
for
PraisonAI
(pip)
Aug 25, 2026
Spring for GraphQL: Annotation Detection Vulnerability
High
CVE-2026-41856
was published
for
org.springframework.graphql:spring-graphql
(Maven)
Jun 11, 2026
Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata
Moderate
CVE-2026-54256
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
Low
CVE-2026-63641
was published
for
magicmirror
(npm)
Aug 18, 2026
MLflow: trace API endpoints lack proper authorization validators
High
CVE-2026-8147
was published
for
mlflow
(pip)
Jul 2, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
High
CVE-2026-54526
was published
for
github.com/argoproj/argo-workflows
(Go)
Aug 13, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
High
CVE-2026-52810
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Spring Data REST has Improper Access Control in its JSON Patch Implementation
High
CVE-2026-41728
was published
for
org.springframework.data:spring-data-rest-core
(Maven)
Jun 10, 2026
Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations
Moderate
CVE-2026-41837
was published
for
org.springframework.data:spring-data-rest-core
(Maven)
Jun 10, 2026
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Moderate
CVE-2026-54765
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Electron: Sandboxed iframes can launch external protocol handlers
Moderate
CVE-2026-70612
was published
for
electron
(npm)
Aug 5, 2026
Electron: Extension tab APIs operate across session boundaries
Moderate
CVE-2026-70602
was published
for
electron
(npm)
Aug 5, 2026
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
Moderate
CVE-2026-70481
was published
for
open-webui
(pip)
Aug 4, 2026
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
High
CVE-2026-70476
was published
for
flowise
(npm)
Aug 4, 2026
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
Moderate
CVE-2026-41847
was published
for
org.springframework:spring-webflux
(Maven)
Jun 9, 2026
MCP Ruby SDK: Ruby SSE Session Poisoning
High
CVE-2026-67431
was published
for
mcp
(RubyGems)
Jul 30, 2026
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
High
CVE-2026-41006
was published
for
org.springframework.hateoas:spring-hateoas
(Maven)
Jun 9, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
Critical
CVE-2026-64863
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
goodoneuz/pay-uz: the /payment/api/editable/update endpoint overwrites existing PHP payment hook files
Critical
CVE-2026-31843
was published
for
goodoneuz/pay-uz
(Composer)
Apr 16, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
ImageMagick: Policy Bypass in script operation due to missing checks
Low
GHSA-vghg-5jrg-2398
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
Low
GHSA-whvh-wf3x-g77j
was published
for
jupyterlab
(pip)
Jul 22, 2026
Netty: Security Control Bypass via CORS Short-Circuit Failure
Moderate
CVE-2026-56746
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API