GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
714 advisories
Filter by severity
Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata
Moderate
CVE-2026-54256
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
Low
CVE-2026-63641
was published
for
magicmirror
(npm)
Aug 18, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
High
CVE-2026-54526
was published
for
github.com/argoproj/argo-workflows
(Go)
Aug 13, 2026
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Moderate
CVE-2026-54765
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Electron: Sandboxed iframes can launch external protocol handlers
Moderate
CVE-2026-70612
was published
for
electron
(npm)
Aug 5, 2026
Electron: Extension tab APIs operate across session boundaries
Moderate
CVE-2026-70602
was published
for
electron
(npm)
Aug 5, 2026
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
Moderate
CVE-2026-70481
was published
for
open-webui
(pip)
Aug 4, 2026
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
High
CVE-2026-70476
was published
for
flowise
(npm)
Aug 4, 2026
MCP Ruby SDK: Ruby SSE Session Poisoning
High
CVE-2026-67431
was published
for
mcp
(RubyGems)
Jul 30, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
Critical
CVE-2026-64863
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
ImageMagick: Policy Bypass in script operation due to missing checks
Low
GHSA-vghg-5jrg-2398
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
Low
GHSA-whvh-wf3x-g77j
was published
for
jupyterlab
(pip)
Jul 22, 2026
Netty: Security Control Bypass via CORS Short-Circuit Failure
Moderate
CVE-2026-56746
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Moderate
CVE-2026-58429
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
High
CVE-2026-58422
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
High
CVE-2026-24451
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Repository Visibility Manipulation via Git Push Options
High
CVE-2026-58437
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
High
CVE-2026-58421
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`
Critical
CVE-2026-20896
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
Moderate
CVE-2026-58507
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54629
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54628
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode
Critical
CVE-2026-50006
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API