GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,752
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,571
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
468 advisories
Filter by severity
multer vulnerable to file size limit bypass via async fileFilter race condition
Low
CVE-2026-77063
was published
for
multer
(npm)
Sep 8, 2026
joi: Prototype pollution via a `__proto__` language key in custom messages
Low
CVE-2026-84368
was published
for
@hapi/joi
(npm)
Sep 8, 2026
joi: object().rename() with a template target can set the validated object's prototype
Low
CVE-2026-84367
was published
for
joi
(npm)
Sep 8, 2026
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
Low
GHSA-6hxq-p678-4hr2
was published
for
@simplewebauthn/server
(npm)
Sep 4, 2026
CKAN MCP Server: Information disclosure via verbose error reflection
Low
CVE-2026-73844
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 3, 2026
MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
Low
CVE-2026-63641
was published
for
magicmirror
(npm)
Aug 18, 2026
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
Low
CVE-2026-71849
was published
for
hono
(npm)
Aug 7, 2026
Mermaid configuration APIs allow prototype pollution
Low
CVE-2026-71438
was published
for
mermaid
(npm)
Aug 6, 2026
Electron: Cross-origin iframe can position native autofill popup
Low
CVE-2026-70600
was published
for
electron
(npm)
Aug 5, 2026
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
Low
CVE-2026-70598
was published
for
electron
(npm)
Aug 5, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Low
CVE-2026-53607
was published
for
apostrophe
(npm)
Jul 31, 2026
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
Low
GHSA-pc2w-4mq8-32qw
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 29, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
Low
GHSA-464c-974j-9xm6
was published
for
@aws-cdk/aws-codebuild
(Go)
Jul 24, 2026
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
Low
GHSA-c2j3-45gr-mqc4
was published
for
dompurify
(npm)
Jul 21, 2026
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
Low
CVE-2026-73425
was published
for
@astrojs/netlify
(npm)
Jul 20, 2026
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
Low
CVE-2026-12590
was published
for
body-parser
(npm)
Jul 20, 2026
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
Low
CVE-2026-59730
was published
for
@astrojs/node
(npm)
Jul 20, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Low
CVE-2026-59727
was published
for
astro
(npm)
Jul 20, 2026
Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
Low
CVE-2026-54335
was published
for
@feathersjs/commons
(npm)
Jul 14, 2026
Waku has an Open Redirect via `unstable_redirect` Helper
Low
CVE-2026-49456
was published
for
waku
(npm)
Jul 8, 2026
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Low
GHSA-2vg6-77g8-24mp
was published
for
@better-auth/scim
(npm)
Jul 7, 2026
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
Low
GHSA-3wqp-prf6-2m72
was published
for
openclaw
(npm)
Jul 2, 2026
@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
Low
GHSA-rp72-5v5q-2446
was published
for
@cardano402/mcp-server
(npm)
Jun 26, 2026
neotoma has tenant isolation gap in relationship query endpoints
Low
GHSA-wrr4-782v-jhwh
was published
for
neotoma
(npm)
Jun 25, 2026
Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components
Low
GHSA-xppm-jmw6-fhmf
was published
for
nuxt
(npm)
Jun 20, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API