GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
109 advisories
Filter by severity
The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to...
Moderate
Unreviewed
CVE-2026-2811
was published
Sep 2, 2026
go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer()...
High
Unreviewed
CVE-2026-75419
was published
Aug 28, 2026
Applications that build a Content-Disposition header value from untrusted input may be vulnerable...
Low
Unreviewed
CVE-2026-59314
was published
Aug 27, 2026
TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to...
High
Unreviewed
CVE-2026-39915
was published
Aug 24, 2026
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters...
Critical
Unreviewed
CVE-2026-67289
was published
Aug 1, 2026
tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to...
Moderate
Unreviewed
CVE-2026-66753
was published
Jul 28, 2026
Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote...
Moderate
Unreviewed
CVE-2026-66746
was published
Jul 28, 2026
swift-nio-http2: Missing CR/LF/NUL validation in header values
Moderate
CVE-2026-64785
was published
for
swift-nio-http2
(Swift)
Jul 24, 2026
Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to...
Moderate
Unreviewed
CVE-2026-63771
was published
Jul 20, 2026
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')...
Low
Unreviewed
CVE-2025-62826
was published
Jul 14, 2026
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')...
Low
Unreviewed
CVE-2025-62675
was published
Jul 14, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
Moderate
CVE-2026-54163
was published
for
secure_headers
(RubyGems)
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
CVE-2026-48596
was published
for
tesla
(Erlang)
Jul 10, 2026
Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is...
Moderate
Unreviewed
CVE-2025-71381
was published
Jul 1, 2026
Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(),...
Moderate
Unreviewed
CVE-2026-56762
was published
Jun 23, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
Moderate
CVE-2026-55766
was published
for
guzzlehttp/psr7
(Composer)
Jun 19, 2026
Kirby: Request header injection in `Http\Remote`
Moderate
CVE-2026-50188
was published
for
getkirby/cms
(Composer)
Jun 18, 2026
aiohttp: CRLF injection in multipart headers
Low
CVE-2026-50269
was published
for
aiohttp
(pip)
Jun 15, 2026
Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection
Moderate
CVE-2026-50630
was published
for
org.apache.cxf:cxf-rt-rs-security-oauth2
(Maven)
Jun 12, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
Moderate
CVE-2026-49214
was published
for
guzzlehttp/psr7
(Composer)
Jun 11, 2026
cowboy and gun affected by an HTTP Request/Response Splitting vulnerability
Moderate
CVE-2026-43966
was published
for
cowboy
(Erlang)
Jun 8, 2026
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
Moderate
CVE-2026-47675
was published
for
hono
(npm)
Jun 4, 2026
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated...
Critical
Unreviewed
CVE-2026-38967
was published
Jun 2, 2026
transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI...
Moderate
Unreviewed
CVE-2026-38978
was published
Jun 2, 2026
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
Low
CVE-2026-44489
was published
for
axios
(npm)
May 29, 2026
ProTip!
Advisories are also available from the
GraphQL API