GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,912
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
147 advisories
Filter by severity
Payload authentication token field handling issue
Critical
CVE-2026-105863
was published
for
payload
(npm)
Oct 7, 2026
Payload: Field-level write access bypass in Payload on MongoDB
High
CVE-2026-106100
was published
for
@payloadcms/db-mongodb
(npm)
Oct 7, 2026
@orpc/zod: Prototype injection in smart coercion
Moderate
CVE-2026-103918
was published
for
@orpc/zod
(npm)
Oct 5, 2026
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)
Moderate
CVE-2026-83557
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Sep 28, 2026
scim-patch: Mutation of Inherited Built-in Method Objects
Moderate
CVE-2026-61834
was published
for
scim-patch
(npm)
Sep 28, 2026
Ash: Private action arguments can be set by user input via string-keyed params and atomic changesets
Moderate
CVE-2026-55736
was published
for
ash
(Erlang)
Sep 24, 2026
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials
High
CVE-2026-76086
was published
for
verbb/formie
(Composer)
Sep 23, 2026
9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
High
CVE-2026-56679
was published
for
9router
(npm)
Sep 23, 2026
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
High
CVE-2026-61591
was published
for
djust
(pip)
Sep 16, 2026
djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler
High
CVE-2026-61598
was published
for
djust
(pip)
Sep 16, 2026
Duplicate Advisory: Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
High
GHSA-w36c-qxrq-v7fw
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
High
CVE-2026-72778
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
High
CVE-2026-69258
was published
for
flowise
(npm)
Aug 4, 2026
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
Moderate
CVE-2026-59888
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jul 21, 2026
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
High
GHSA-7jvp-hj45-2f2m
was published
for
Scriban
(NuGet)
Jul 6, 2026
Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
High
CVE-2026-50281
was published
for
craftcms/cms
(Composer)
Jul 2, 2026
jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields
Moderate
CVE-2026-54516
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
Moderate
CVE-2026-54515
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
High
CVE-2026-54351
was published
for
@budibase/server
(npm)
Jun 22, 2026
flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
High
CVE-2026-55091
was published
for
flat-to-nested
(npm)
Jun 19, 2026
spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError
Moderate
GHSA-2jx3-65f3-xr8r
was published
for
spomky-labs/otphp
(Composer)
Jun 18, 2026
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
Critical
CVE-2026-48150
was published
for
@budibase/server
(npm)
Jun 12, 2026
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
High
CVE-2026-46517
was published
for
lmdeploy
(pip)
May 21, 2026
Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification
Moderate
GHSA-59fh-9f3p-7m39
was published
for
flowise
(npm)
May 20, 2026
Drupal core allows Object Injection
Moderate
CVE-2026-6366
was published
for
drupal/core
(Composer)
May 20, 2026
ProTip!
Advisories are also available from the
GraphQL API