GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,912
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
192 advisories
Filter by severity
Payload authentication token field handling issue
Critical
CVE-2026-105863
was published
for
payload
(npm)
Oct 7, 2026
Payload: Field-level write access bypass in Payload on MongoDB
High
CVE-2026-106100
was published
for
@payloadcms/db-mongodb
(npm)
Oct 7, 2026
@orpc/zod: Prototype injection in smart coercion
Moderate
CVE-2026-103918
was published
for
@orpc/zod
(npm)
Oct 5, 2026
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)
Moderate
CVE-2026-83557
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Sep 28, 2026
scim-patch: Mutation of Inherited Built-in Method Objects
Moderate
CVE-2026-61834
was published
for
scim-patch
(npm)
Sep 28, 2026
Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated...
Moderate
Unreviewed
CVE-2026-93364
was published
Sep 25, 2026
Ash: Private action arguments can be set by user input via string-keyed params and atomic changesets
Moderate
CVE-2026-55736
was published
for
ash
(Erlang)
Sep 24, 2026
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials
High
CVE-2026-76086
was published
for
verbb/formie
(Composer)
Sep 23, 2026
9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
High
CVE-2026-56679
was published
for
9router
(npm)
Sep 23, 2026
CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty...
High
Unreviewed
CVE-2026-93752
was published
Sep 18, 2026
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
High
CVE-2026-61591
was published
for
djust
(pip)
Sep 16, 2026
djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler
High
CVE-2026-61598
was published
for
djust
(pip)
Sep 16, 2026
SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action...
Critical
Unreviewed
CVE-2026-72710
was published
Sep 11, 2026
There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is...
High
Unreviewed
CVE-2026-59284
was published
Aug 27, 2026
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against...
High
Unreviewed
CVE-2026-47849
was published
Aug 27, 2026
Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root...
Moderate
Unreviewed
CVE-2026-47850
was published
Aug 27, 2026
The frontend management plugin attributed a newly created event to the submitting user's...
High
Unreviewed
CVE-2026-77144
was published
Aug 25, 2026
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an...
High
Unreviewed
CVE-2026-78416
was published
Aug 24, 2026
Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly...
High
Unreviewed
CVE-2026-49428
was published
Aug 19, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the...
Moderate
Unreviewed
CVE-2026-72655
was published
Aug 13, 2026
A flaw was found in the `search-v2-operator` component. A user with specific administrative...
High
Unreviewed
CVE-2026-71473
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
High
Unreviewed
CVE-2026-17095
was published
Aug 12, 2026
Duplicate Advisory: Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
High
GHSA-w36c-qxrq-v7fw
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a...
High
Unreviewed
CVE-2026-18617
was published
Aug 10, 2026
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user...
Moderate
Unreviewed
CVE-2026-17598
was published
Aug 7, 2026
ProTip!
Advisories are also available from the
GraphQL API