GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
147 advisories
Filter by severity
Payload authentication token field handling issue
Critical
CVE-2026-105863
was published
for
payload
(npm)
Oct 7, 2026
Payload: Field-level write access bypass in Payload on MongoDB
High
CVE-2026-106100
was published
for
@payloadcms/db-mongodb
(npm)
Oct 7, 2026
@orpc/zod: Prototype injection in smart coercion
Moderate
CVE-2026-103918
was published
for
@orpc/zod
(npm)
Oct 5, 2026
Prototype Pollution via parse() in NodeJS flatted
High
CVE-2026-33228
was published
for
flatted
(npm)
Mar 19, 2026
locutus is vulnerable to Prototype Pollution
Critical
CVE-2026-25521
was published
for
locutus
(npm)
Feb 2, 2026
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)
Moderate
CVE-2026-83557
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Sep 28, 2026
scim-patch: Mutation of Inherited Built-in Method Objects
Moderate
CVE-2026-61834
was published
for
scim-patch
(npm)
Sep 28, 2026
Ash: Private action arguments can be set by user input via string-keyed params and atomic changesets
Moderate
CVE-2026-55736
was published
for
ash
(Erlang)
Sep 24, 2026
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials
High
CVE-2026-76086
was published
for
verbb/formie
(Composer)
Sep 23, 2026
9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
High
CVE-2026-56679
was published
for
9router
(npm)
Sep 23, 2026
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
High
CVE-2026-61591
was published
for
djust
(pip)
Sep 16, 2026
djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler
High
CVE-2026-61598
was published
for
djust
(pip)
Sep 16, 2026
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
High
CVE-2026-72778
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Duplicate Advisory: Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
High
GHSA-w36c-qxrq-v7fw
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
High
CVE-2026-46517
was published
for
lmdeploy
(pip)
May 21, 2026
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
High
CVE-2026-69258
was published
for
flowise
(npm)
Aug 4, 2026
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
Moderate
CVE-2026-59888
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jul 21, 2026
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
High
CVE-2026-54351
was published
for
@budibase/server
(npm)
Jun 22, 2026
jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields
Moderate
CVE-2026-54516
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
Moderate
CVE-2026-54515
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
High
CVE-2026-46479
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover
High
CVE-2026-46478
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover
High
CVE-2026-46477
was published
for
flowise
(npm)
May 14, 2026
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
High
GHSA-7jvp-hj45-2f2m
was published
for
Scriban
(NuGet)
Jul 6, 2026
Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
High
CVE-2026-50281
was published
for
craftcms/cms
(Composer)
Jul 2, 2026
ProTip!
Advisories are also available from the
GraphQL API