GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
3,338 advisories
Filter by severity
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
Moderate
CVE-2026-61799
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
Moderate
CVE-2026-63336
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
RabbitMQ Java client malformed body frame triggers raw command assembler exception
Moderate
CVE-2026-63335
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
Moderate
CVE-2026-54147
was published
for
org.http4k:http4k-security-digest
(Maven)
Aug 17, 2026
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
Moderate
CVE-2026-59903
was published
for
io.netty:netty-codec-http
(Maven)
Aug 17, 2026
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
Moderate
CVE-2026-56818
was published
for
io.netty:netty-codec-redis
(Maven)
Aug 7, 2026
jsoup: Cleaner may expose markup with custom raw-text elements
Moderate
CVE-2026-71497
was published
for
org.jsoup:jsoup
(Maven)
Aug 6, 2026
core-geonetwork has an Open Redirect Bypass
Moderate
CVE-2026-53573
was published
for
org.geonetwork-opensource:geonetwork
(Maven)
Jul 31, 2026
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Moderate
CVE-2026-64607
was published
for
org.apache.httpcomponents.client5:httpclient5
(Maven)
Jul 31, 2026
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Moderate
CVE-2026-54704
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Moderate
CVE-2026-54712
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
veraPDF Parser DoS via PostScript Type 1 Font Programs
Moderate
CVE-2026-54081
was published
for
org.verapdf:parser
(Maven)
Jul 29, 2026
veraPDF Parser DoS via PostScript CMap Streams
Moderate
CVE-2026-54080
was published
for
org.verapdf:parser
(Maven)
Jul 29, 2026
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
Moderate
CVE-2026-54082
was published
for
org.verapdf:validation-model
(Maven)
Jul 29, 2026
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
Moderate
CVE-2023-37465
was published
for
org.xwiki.contrib:discussions-server
(Maven)
Jul 27, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
Moderate
CVE-2026-62280
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jul 24, 2026
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
Moderate
CVE-2026-73508
was published
for
io.netty:netty-codec-dns
(Maven)
Jul 24, 2026
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
Moderate
CVE-2026-59949
was published
for
at.yawk.lz4:lz4-java
(Maven)
Jul 24, 2026
c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets
Moderate
CVE-2026-55223
was published
for
com.mchange:c3p0
(Maven)
Jul 23, 2026
Eclipse Jetty: Path parameter traversal
Moderate
CVE-2026-8384
was published
for
org.eclipse.jetty:jetty-util
(Maven)
Jul 22, 2026
Eclipse Jetty: HTTP Authority/Host mismatch
Moderate
CVE-2026-6790
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
Moderate
CVE-2026-10051
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
Moderate
CVE-2026-59921
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Netty: STOMP CONNECT Frame Header Injection in Netty
Moderate
CVE-2026-59920
was published
for
io.netty:netty-codec-stomp
(Maven)
Jul 22, 2026
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
Moderate
CVE-2026-59919
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API