GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
73 advisories
Filter by severity
vm2: `allowAsync: false` can be bypassed through Promise thenable assimilation in VM and NodeVM
High
CVE-2026-92959
was published
for
vm2
(npm)
Oct 5, 2026
Socket.IO: Engine.IO Protocol Revision Mismatch DoS
High
CVE-2026-102599
was published
for
engine.io
(npm)
Sep 29, 2026
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
Moderate
CVE-2026-85709
was published
for
lightrag-hku
(pip)
Sep 22, 2026
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service
Moderate
CVE-2026-77561
was published
for
github.com/steveiliop56/tinyauth
(Go)
Sep 22, 2026
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions
Moderate
CVE-2026-77250
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files
High
CVE-2026-77253
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
High
CVE-2026-81876
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.r5
(Maven)
Sep 17, 2026
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
High
CVE-2026-81875
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.r5
(Maven)
Sep 17, 2026
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured
High
CVE-2026-78682
was published
for
nltk
(pip)
Sep 8, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
Moderate
CVE-2026-63733
was published
for
surrealdb-core
(Rust)
Sep 4, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
High
CVE-2026-63735
was published
for
surrealdb
(Rust)
Sep 4, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
CVE-2026-75911
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
High
CVE-2026-75859
was published
for
codewhale
(npm)
Sep 4, 2026
VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root
Moderate
CVE-2026-61625
was published
for
github.com/VictoriaMetrics/VictoriaMetrics
(Go)
Sep 3, 2026
elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections
Moderate
CVE-2026-81890
was published
for
studio-42/elfinder
(Composer)
Sep 2, 2026
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
Moderate
CVE-2026-55678
was published
for
github.com/basekick-labs/arc
(Go)
Aug 28, 2026
YOURLS has stored XSS in referrer statistics chart via crafted Referer header
High
CVE-2026-63135
was published
for
yourls/yourls
(Composer)
Aug 21, 2026
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
High
CVE-2026-63124
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
Moderate
CVE-2026-61799
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
High
CVE-2026-61798
was published
for
io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl
(Maven)
Aug 20, 2026
NocoBase backup restore schema name allows command injection
Moderate
CVE-2026-55410
was published
for
@nocobase/plugin-backups
(npm)
Aug 20, 2026
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables
Moderate
CVE-2026-63640
was published
for
magicmirror
(npm)
Aug 18, 2026
MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
Low
CVE-2026-63641
was published
for
magicmirror
(npm)
Aug 18, 2026
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
Moderate
CVE-2026-54706
was published
for
onionshare-cli
(pip)
Jul 31, 2026
OnionShare Receive mode writes uploaded files even when file uploads are disabled
Moderate
CVE-2026-54707
was published
for
onionshare-cli
(pip)
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API