GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
7,706 advisories
Filter by severity
knowns OS Command Injection via Insecure LSP Binary Path Config in .knowns/config.json
High
CVE-2026-86540
was published
for
knowns
(npm)
Oct 6, 2026
Payload didn't enforce field-level password update restrictions
High
CVE-2026-105855
was published
for
payload
(npm)
Oct 6, 2026
Payload: ReDoS in Multipart Content-Type Validation
High
CVE-2026-105854
was published
for
payload
(npm)
Oct 6, 2026
Payload vulnerable to API key disclosure through ordinary document reads
High
CVE-2026-105849
was published
for
payload
(npm)
Oct 6, 2026
Payload Ecommerce has an order confirmation validation issue
High
CVE-2026-105850
was published
for
@payloadcms/plugin-ecommerce
(npm)
Oct 6, 2026
Payload relationship-query authorization bypass
Moderate
CVE-2026-105852
was published
for
payload
(npm)
Oct 6, 2026
Payload: Token refresh and password reset responses may expose restricted user fields
High
CVE-2026-105853
was published
for
payload
(npm)
Oct 6, 2026
Payload: Field access control bypass on auth collections
Critical
CVE-2026-105851
was published
for
payload
(npm)
Oct 6, 2026
Payload: Insufficient Access Control in Stripe REST Proxy
Moderate
CVE-2026-105848
was published
for
@payloadcms/plugin-stripe
(npm)
Oct 6, 2026
Payload: Improper access control for MCP API keys
High
CVE-2026-105806
was published
for
@payloadcms/plugin-mcp
(npm)
Oct 6, 2026
Payload: Prototype pollution in Payload Import Export plugin
Critical
CVE-2026-105844
was published
for
@payloadcms/plugin-import-export
(npm)
Oct 6, 2026
Payload: SQL Injection in SQLite and Postgres
Critical
CVE-2026-105845
was published
for
payload
(npm)
Oct 6, 2026
Payload: Untrusted redirect URL parameter exploit
Moderate
CVE-2026-105846
was published
for
@payloadcms/next
(npm)
Oct 6, 2026
Payload: Polymorphic join queries could disclose hidden fields
High
CVE-2026-105847
was published
for
payload
(npm)
Oct 6, 2026
Payload: Password hashes use insufficient PBKDF2 iterations
Moderate
CVE-2026-105804
was published
for
payload
(npm)
Oct 6, 2026
Payload: Sort queries could expose protected field information
Moderate
CVE-2026-105805
was published
for
payload
(npm)
Oct 6, 2026
MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
High
CVE-2026-104850
was published
for
@modelcontextprotocol/client
(npm)
Oct 6, 2026
i18next-http-backend incomplete URL validation permits SSRF
Low
CVE-2026-105800
was published
for
i18next-http-backend
(npm)
Oct 6, 2026
LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values
Low
CVE-2026-105799
was published
for
@langchain/redis
(npm)
Oct 6, 2026
sharp : Vulnerability in librsvg dependency CVE-2026-96889
High
GHSA-wq5f-xc86-pv6w
was published
for
sharp
(npm)
Oct 6, 2026
shell-quote: `quote()` command injection via a line terminator in a token after a `{ comment }` token
Critical
CVE-2026-102422
was published
for
shell-quote
(npm)
Oct 6, 2026
pbkdf2 rehashes long passwords on every iteration, enabling denial of service
Moderate
CVE-2026-102414
was published
for
pbkdf2
(npm)
Oct 6, 2026
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
Critical
CVE-2026-102829
was published
for
@simple-git/argv-parser
(npm)
Oct 5, 2026
simple-git unsafe-operation guard does not block trailer command configuration
Critical
CVE-2026-102828
was published
for
simple-git
(npm)
Oct 5, 2026
simple-git allows command execution through unblocked Git configuration includes
High
CVE-2026-102826
was published
for
simple-git
(npm)
Oct 5, 2026
ProTip!
Advisories are also available from the
GraphQL API