GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,536
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34,555 advisories
Filter by severity
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
Moderate
GHSA-hjwh-xvfw-qrwj
was published
for
mcp-searxng
(npm)
Aug 19, 2026
Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
High
CVE-2026-62673
was published
for
getgrav/grav
(Composer)
Aug 19, 2026
Snipe-IT: Stored DOM XSS via table selected-count IDs
Moderate
CVE-2026-61807
was published
for
snipe/snipe-it
(Composer)
Aug 19, 2026
Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET
Moderate
CVE-2026-55703
was published
for
snipe/snipe-it
(Composer)
Aug 19, 2026
Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover
High
CVE-2026-55694
was published
for
snipe/snipe-it
(Composer)
Aug 19, 2026
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
High
CVE-2024-45747
was published
for
org.geoserver.web:gs-web-app
(Maven)
Aug 19, 2026
SearXNG MCP Server: Additional hardened-mode SSRF bypasses
Moderate
CVE-2026-54689
was published
for
mcp-searxng
(npm)
Aug 19, 2026
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Moderate
CVE-2026-54688
was published
for
mcp-searxng
(npm)
Aug 19, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing
High
CVE-2026-53966
was published
for
org.xwiki.platform:xwiki-platform-livedata-livetable
(Maven)
Aug 19, 2026
MCP PHP SDK: client HttpTransport SSE buffer (sseBuffer .= chunk) grows unbounded when server withholds the event delimiter
High
CVE-2026-53965
was published
for
mcp/sdk
(Composer)
Aug 19, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
High
CVE-2026-53964
was published
for
document-merge-service
(pip)
Aug 19, 2026
Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
High
CVE-2026-53957
was published
for
@contentful/mcp-server
(npm)
Aug 19, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
High
CVE-2026-53951
was published
for
copier
(pip)
Aug 19, 2026
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
Moderate
CVE-2026-53941
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
Aug 19, 2026
block_buffer: panic corrupts inline buffer position
Moderate
GHSA-qwgh-2vcv-g2f7
was published
for
block_buffer
(Rust)
Aug 19, 2026
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-rr55-jp92-8wp2
was published
for
claude-faf-mcp
(npm)
Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-j4r7-8ph4-43g3
was published
for
faf-mcp
(npm)
Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
High
GHSA-cc2g-gq8c-r332
was published
for
grok-faf-mcp
(npm)
Aug 19, 2026
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
Moderate
CVE-2026-55236
was published
for
langgraph-api
(pip)
Aug 19, 2026
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
Moderate
CVE-2026-55235
was published
for
langgraph-api
(pip)
Aug 19, 2026
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
Moderate
CVE-2026-73974
was published
for
linuxfabrik-lib
(pip)
Aug 18, 2026
moby/go-archive: Crafted tar archive can write outside the extraction directory
High
CVE-2026-17106
was published
for
github.com/moby/go-archive
(Go)
Aug 18, 2026
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
High
GHSA-7gww-x7fh-jf9j
was published
for
librenms/librenms
(Composer)
Aug 18, 2026
LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users
Moderate
GHSA-7cj5-v4pp-v632
was published
for
librenms/librenms
(Composer)
Aug 18, 2026
ProTip!
Advisories are also available from the
GraphQL API