GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,533
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34,479 advisories
Filter by severity
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
High
CVE-2026-69148
was published
for
mlflow
(npm)
Aug 17, 2026
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
Moderate
CVE-2026-69146
was published
for
mlflow
(npm)
Aug 17, 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
Critical
CVE-2026-64849
was published
for
mlflow
(pip)
Aug 17, 2026
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
High
CVE-2026-56677
was published
for
9router
(npm)
Aug 17, 2026
http4k: `DigestAuthProvider.verify` did not bind to request URI
High
CVE-2026-54148
was published
for
org.http4k:http4k-security-digest
(Maven)
Aug 17, 2026
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
Moderate
CVE-2026-54147
was published
for
org.http4k:http4k-security-digest
(Maven)
Aug 17, 2026
chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
Moderate
CVE-2026-53766
was published
for
chrome-devtools-mcp
(npm)
Aug 17, 2026
package pkcs12: Authentication bypass in Decode functions
Moderate
GHSA-mpwr-8vm7-h73f
was published
for
software.sslmate.com/src/go-pkcs12
(Go)
Aug 17, 2026
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
High
CVE-2026-53752
was published
for
org.docx4j:docx4j-core
(Maven)
Aug 17, 2026
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
High
CVE-2026-53659
was published
for
org.http4k:http4k-core
(Maven)
Aug 17, 2026
atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard
High
GHSA-j659-8xh6-5pq5
was published
for
atomic-agents-stack
(pip)
Aug 17, 2026
atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
High
GHSA-xhcr-cqfr-m3hv
was published
for
atomic-agents-stack
(pip)
Aug 17, 2026
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
Moderate
CVE-2026-59903
was published
for
io.netty:netty-codec-http
(Maven)
Aug 17, 2026
Netty: Memory Exhaustion in SctpMessageCompletionHandler
High
CVE-2026-59902
was published
for
io.netty:netty-transport-sctp
(Maven)
Aug 17, 2026
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
High
GHSA-fhgh-wq4q-r37x
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
High
CVE-2026-59893
was published
for
sqlparse
(pip)
Aug 17, 2026
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
High
CVE-2026-54284
was published
for
sqlparse
(pip)
Aug 17, 2026
Etherpad has stored XSS in HTML export via unescaped attribute-pool values
High
CVE-2026-55090
was published
for
ep_etherpad-lite
(npm)
Aug 17, 2026
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
Moderate
GHSA-92hr-gmr6-h8cp
was published
for
ep_etherpad-lite
(npm)
Aug 17, 2026
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability
Moderate
CVE-2026-55062
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
uniget CLI has an EDITOR Command Injection
Moderate
CVE-2026-55061
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
High
GHSA-v836-6xw4-9cx3
was published
for
vm2
(npm)
Aug 17, 2026
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
Critical
GHSA-m5w8-4gq2-6f8x
was published
for
vm2
(npm)
Aug 17, 2026
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
Critical
CVE-2026-47698
was published
for
vm2
(npm)
Aug 17, 2026
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
Critical
CVE-2026-47686
was published
for
vm2
(npm)
Aug 17, 2026
ProTip!
Advisories are also available from the
GraphQL API