GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,533
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34,479 advisories
Filter by severity
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
High
CVE-2026-47683
was published
for
vm2
(npm)
Aug 17, 2026
sqlparse: Quadratic O(n²) DoS in group_comments
High
CVE-2026-71491
was published
for
sqlparse
(pip)
Aug 17, 2026
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
Moderate
CVE-2026-68520
was published
for
glances
(pip)
Aug 17, 2026
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
High
CVE-2026-68519
was published
for
glances
(pip)
Aug 17, 2026
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
High
CVE-2026-62982
was published
for
glances
(pip)
Aug 17, 2026
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
Moderate
CVE-2026-59894
was published
for
sqlparse
(pip)
Aug 17, 2026
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
Moderate
CVE-2026-68517
was published
for
glances
(pip)
Aug 17, 2026
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
Moderate
CVE-2026-45099
was published
for
github.com/gruntwork-io/terragrunt
(Go)
Aug 17, 2026
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
High
CVE-2026-68518
was published
for
glances
(pip)
Aug 17, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
Moderate
CVE-2026-64865
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting)
Critical
CVE-2026-71479
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users
Moderate
CVE-2026-64866
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
High
CVE-2026-64868
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
Critical
CVE-2026-64859
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
High
CVE-2026-53728
was published
for
@medplum/core
(npm)
Aug 17, 2026
conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target
Critical
CVE-2026-55158
was published
for
wktk/conflibot
(GitHub Actions)
Aug 17, 2026
DeepmergeTS has stack exhaustion when merging recursive object graphs
High
CVE-2026-40345
was published
for
deepmerge-ts
(npm)
Aug 17, 2026
s2n-quic has excessive memory allocation
Moderate
CVE-2026-10740
was published
for
s2n-quic
(Rust)
Aug 14, 2026
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
Moderate
CVE-2026-55156
was published
for
@ooples/token-optimizer-mcp
(npm)
Aug 14, 2026
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
High
CVE-2026-55157
was published
for
@ooples/token-optimizer-mcp
(npm)
Aug 14, 2026
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Moderate
CVE-2026-53708
was published
for
mcp-contextforge-gateway
(pip)
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
Moderate
GHSA-8rw6-p7m8-63jp
was published
for
surrealdb
(Rust)
Aug 14, 2026
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
High
CVE-2026-55153
was published
for
com.mchange:mchange-commons-java
(Maven)
Aug 14, 2026
OpenAM Insecure SSO Cookie Initialization
High
CVE-2026-53660
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Aug 14, 2026
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Moderate
CVE-2026-53658
was published
for
github.com/hyperledger/fabric-ca
(Go)
Aug 14, 2026
ProTip!
Advisories are also available from the
GraphQL API