GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,435
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,690
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
3,099 advisories
Filter by severity
quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper class
Moderate
GHSA-jx2w-vp7f-456q
was published
for
io.quarkiverse.openapi.generator:quarkus-openapi-generator
(Maven)
Apr 8, 2026
Emissary has a Path Traversal via Blacklist Bypass in Configuration API
Moderate
CVE-2026-35583
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 8, 2026
PowerJob's GroovyEvaluator.evaluate endpoint vulnerable to code injection
Moderate
CVE-2026-5739
was published
for
tech.powerjob:powerjob-server-starter
(Maven)
Apr 7, 2026
PowerJob vulnerable to SQL injection
Moderate
CVE-2026-5736
was published
for
tech.powerjob:powerjob-server-starter
(Maven)
Apr 7, 2026
Emissary has Stored XSS via Navigation Template Link Injection
Moderate
CVE-2026-35571
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 7, 2026
Apache Cassandra has sensitive Information Leak in cqlsh
Moderate
CVE-2026-27315
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Apr 7, 2026
Apache ActiveMQ: Improper validation and restriction of a classpath path name
Moderate
CVE-2026-33227
was published
for
org.apache.activemq:activemq-all
(Maven)
Apr 7, 2026
Keycloak: Replay of action tokens via improper handling of single-use entries
Moderate
CVE-2026-4325
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)
Moderate
CVE-2026-34237
was published
for
io.modelcontextprotocol.sdk:mcp-core
(Maven)
Mar 30, 2026
FHIR Validator: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing
Moderate
CVE-2026-34360
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.core
(Maven)
Mar 30, 2026
Keycloak: Missing Role Enforcement on UMA 2.0 Permission Ticket Endpoint Leads to Information Disclosure
Moderate
CVE-2026-3190
was published
for
org.keycloak:keycloak-model-jpa
(Maven)
Mar 26, 2026
Keycloak: manage-clients permission escalates to full realm admin access
Moderate
CVE-2026-3121
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 26, 2026
sbt: Source dependency feature (via crafted VCS URL) leads to arbitrary code execution on Windows
Moderate
CVE-2026-32948
was published
for
org.scala-sbt:sbt
(Maven)
Mar 24, 2026
Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests
Moderate
CVE-2026-3260
was published
for
io.undertow:undertow-core
(Maven)
Mar 24, 2026
Keycloak has Improper Access Control allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false
Moderate
CVE-2026-4628
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 23, 2026
Spring Framework Improper Path Limitation with Script View Templates
Moderate
CVE-2026-22737
was published
for
org.springframework:spring-webflux
(Maven)
Mar 20, 2026
Jenkins LoadNinja Plugin does not mask LoadNinja API keys displayed on the job configuration form
Moderate
CVE-2026-33004
was published
for
org.jenkins-ci.plugins:loadninja
(Maven)
Mar 18, 2026
Jenkins LoadNinja Plugin stores LoadNinja API keys unencrypted in job config.xml files
Moderate
CVE-2026-33003
was published
for
org.jenkins-ci.plugins:loadninja
(Maven)
Mar 18, 2026
Keycloak: Denial of Service due to excessive SAMLRequest decompression
Moderate
CVE-2026-2575
was published
for
org.keycloak:keycloak-saml-adapter-core
(Maven)
Mar 18, 2026
Apache Livy: Unauthorized directory access
Moderate
CVE-2025-66249
was published
for
org.apache.livy:livy-server
(Maven)
Mar 13, 2026
Apache Livy: Restrict file access
Moderate
CVE-2025-60012
was published
for
org.apache.livy:livy-server
(Maven)
Mar 13, 2026
Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API
Moderate
CVE-2026-3429
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 11, 2026
Vaadin Vulnerable to Authentication Bypass When Accessing the /VAADIN Endpoint Without a Trailing Slash
Moderate
CVE-2026-2742
was published
for
com.vaadin:flow-server
(Maven)
Mar 10, 2026
Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function
Moderate
CVE-2026-23907
was published
for
org.apache.pdfbox:pdfbox-examples
(Maven)
Mar 10, 2026
Cloudfoundry UAA has logic error in the token revocation endpoint implementation
Moderate
CVE-2026-22723
was published
for
org.cloudfoundry.identity:cloudfoundry-identity-server
(Maven)
Mar 5, 2026
ProTip!
Advisories are also available from the
GraphQL API