GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,752
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,571
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
1,152 advisories
Filter by severity
decidim-elections: Election question titles allow stored script execution
Moderate
CVE-2026-44282
was published
for
decidim-elections
(RubyGems)
Sep 9, 2026
Cassandra Web - Remote File Read
High
CVE-2020-36939
was published
for
cassandra-web
(RubyGems)
Jan 27, 2026
Mail: Email address spoofing via malformed RFC 2047 encoded-words
Moderate
CVE-2026-63435
was published
for
mail
(RubyGems)
Sep 2, 2026
Nokogiri CSS selector tokenizer has regular expression backtracking
High
CVE-2026-79770
was published
for
nokogiri
(RubyGems)
May 6, 2026
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking
High
GHSA-5jhf-fpp7-v2pv
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
Nokogiri XSLT transform has a memory leak
Moderate
CVE-2026-79771
was published
for
nokogiri
(RubyGems)
May 6, 2026
Duplicate Advisory: Nokogiri XSLT transform has a memory leak
Moderate
GHSA-rh9x-7xjc-vwx2
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
Nokogiri does not check the return value from xmlC14NExecute
Moderate
CVE-2026-79772
was published
for
nokogiri
(RubyGems)
Feb 18, 2026
Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute
Moderate
GHSA-xqqh-3w52-q8p7
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
Critical
CVE-2026-55107
was published
for
kobako
(RubyGems)
Aug 18, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Moderate
CVE-2026-54465
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
websocket-driver: Resource limit bypass via message compression
Moderate
CVE-2026-54464
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Moderate
CVE-2026-54463
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Moderate
CVE-2026-73648
was published
for
rails-html-sanitizer
(RubyGems)
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Low
CVE-2026-73491
was published
for
loofah
(RubyGems)
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
Moderate
CVE-2026-73490
was published
for
loofah
(RubyGems)
Jul 21, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
Moderate
CVE-2026-73428
was published
for
action_text-trix
(RubyGems)
Jul 24, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
CVE-2026-73427
was published
for
action_text-trix
(RubyGems)
Mar 29, 2026
Trix has a Stored XSS vulnerability through serialized attributes
Moderate
CVE-2026-73426
was published
for
action_text-trix
(RubyGems)
Mar 12, 2026
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Low
CVE-2026-71847
was published
for
json
(RubyGems)
Aug 7, 2026
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
High
CVE-2026-54904
was published
for
concurrent-ruby
(RubyGems)
Jun 19, 2026
katello: missing repository authorization in content_uploads exposes cross-product content existence
Moderate
CVE-2026-12515
was published
for
katello
(RubyGems)
Jun 17, 2026
guard-livereload has a directory traversal vulnerability
Moderate
CVE-2016-1000305
was published
for
guard-livereload
(RubyGems)
Jul 31, 2026
Savon::Model evaluates WSDL operation names as Ruby source
High
CVE-2026-53510
was published
for
savon
(RubyGems)
Jul 31, 2026
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
Low
GHSA-wjv4-x9w8-wm3h
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API