GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,533
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
3,328 advisories
Filter by severity
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
Moderate
CVE-2026-54147
was published
for
org.http4k:http4k-security-digest
(Maven)
Aug 17, 2026
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
Moderate
CVE-2026-59903
was published
for
io.netty:netty-codec-http
(Maven)
Aug 17, 2026
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
Moderate
CVE-2026-56818
was published
for
io.netty:netty-codec-redis
(Maven)
Aug 7, 2026
jsoup: Cleaner may expose markup with custom raw-text elements
Moderate
CVE-2026-71497
was published
for
org.jsoup:jsoup
(Maven)
Aug 6, 2026
core-geonetwork has an Open Redirect Bypass
Moderate
CVE-2026-53573
was published
for
org.geonetwork-opensource:geonetwork
(Maven)
Jul 31, 2026
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Moderate
CVE-2026-64607
was published
for
org.apache.httpcomponents.client5:httpclient5
(Maven)
Jul 31, 2026
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Moderate
CVE-2026-54704
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Moderate
CVE-2026-54712
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
veraPDF Parser DoS via PostScript Type 1 Font Programs
Moderate
CVE-2026-54081
was published
for
org.verapdf:parser
(Maven)
Jul 29, 2026
veraPDF Parser DoS via PostScript CMap Streams
Moderate
CVE-2026-54080
was published
for
org.verapdf:parser
(Maven)
Jul 29, 2026
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
Moderate
CVE-2026-54082
was published
for
org.verapdf:validation-model
(Maven)
Jul 29, 2026
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
Moderate
CVE-2023-37465
was published
for
org.xwiki.contrib:discussions-server
(Maven)
Jul 27, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
Moderate
CVE-2026-62280
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jul 24, 2026
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
Moderate
CVE-2026-73508
was published
for
io.netty:netty-codec-dns
(Maven)
Jul 24, 2026
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
Moderate
CVE-2026-59949
was published
for
at.yawk.lz4:lz4-java
(Maven)
Jul 24, 2026
c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets
Moderate
CVE-2026-55223
was published
for
com.mchange:c3p0
(Maven)
Jul 23, 2026
Eclipse Jetty: Path parameter traversal
Moderate
CVE-2026-8384
was published
for
org.eclipse.jetty:jetty-util
(Maven)
Jul 22, 2026
Eclipse Jetty: HTTP Authority/Host mismatch
Moderate
CVE-2026-6790
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
Moderate
CVE-2026-10051
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
Moderate
CVE-2026-59921
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Netty: STOMP CONNECT Frame Header Injection in Netty
Moderate
CVE-2026-59920
was published
for
io.netty:netty-codec-stomp
(Maven)
Jul 22, 2026
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
Moderate
CVE-2026-59919
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jul 22, 2026
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
Moderate
CVE-2026-59900
was published
for
io.netty:netty-codec-http2
(Maven)
Jul 22, 2026
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
Moderate
CVE-2026-59899
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
Moderate
CVE-2026-59898
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API