GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
38 advisories
Filter by severity
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
High
CVE-2026-86049
was published
for
jupyter_server
(pip)
Sep 17, 2026
Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
Moderate
CVE-2026-58657
was published
for
getgrav/grav
(Composer)
Sep 16, 2026
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
Low
GHSA-rf68-8gjr-36q7
was published
for
github.com/nezhahq/nezha
(Go)
Sep 15, 2026
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
High
CVE-2026-59973
was published
for
@frontmcp/adapters
(npm)
Sep 11, 2026
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
High
CVE-2026-59161
was published
for
github.com/xuri/excelize
(Go)
Sep 10, 2026
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
Moderate
CVE-2026-59162
was published
for
github.com/xuri/excelize
(Go)
Sep 10, 2026
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
Moderate
CVE-2026-73262
was published
for
prowler
(pip)
Sep 8, 2026
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
High
CVE-2026-55596
was published
for
@platejs/media
(npm)
Aug 25, 2026
MobSF has SSRF port restriction bypass in assetlinks_check
Low
CVE-2026-68927
was published
for
mobsf
(pip)
Aug 18, 2026
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
High
CVE-2026-71315
was published
for
nuxt
(npm)
Aug 5, 2026
Ghost: Server-Side Request Forgery in Image Fetching
Moderate
CVE-2026-70591
was published
for
ghost
(npm)
Aug 4, 2026
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
Moderate
CVE-2026-70484
was published
for
open-webui
(pip)
Aug 4, 2026
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Moderate
GHSA-v6w6-358x-2433
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
Moderate
CVE-2026-62323
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
High
GHSA-xg5g-26x8-cvf4
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
High
GHSA-xcx6-4f2g-hhgx
was published
for
@budibase/server
(npm)
Jul 24, 2026
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
High
CVE-2026-59221
was published
for
open-webui
(pip)
Jul 24, 2026
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
High
CVE-2026-55502
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Low
CVE-2026-59215
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
High
CVE-2026-59714
was published
for
open-webui
(pip)
Jul 24, 2026
Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
Moderate
CVE-2026-59897
was published
for
hono
(npm)
Jul 21, 2026
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
Moderate
CVE-2026-55668
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
Koel has SSRF through Authenticated Subsonic podcast feed URLs
Moderate
GHSA-8q6q-m837-fv64
was published
for
phanan/koel
(Composer)
Jul 15, 2026
n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
Moderate
CVE-2026-55608
was published
for
n8n-mcp
(npm)
Jul 14, 2026
Kite has an authenticated cluster RBAC bypass in /api/v1/overview
Moderate
CVE-2026-53487
was published
for
github.com/zxh326/kite
(Go)
Jul 7, 2026
ProTip!
Advisories are also available from the
GraphQL API