GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,020 advisories
Filter by severity
Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
Moderate
GHSA-6vj9-mwq6-2f5v
was published
for
nodemailer
(npm)
Sep 28, 2026
undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
Moderate
CVE-2026-85024
was published
for
undici
(npm)
Sep 28, 2026
multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
Moderate
CVE-2026-88932
was published
for
multer
(npm)
Sep 28, 2026
morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
Moderate
CVE-2026-87859
was published
for
morgan
(npm)
Sep 28, 2026
Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
High
CVE-2026-101895
was published
for
@angular/platform-server
(npm)
Sep 28, 2026
fast-uri vulnerable to authority injection via an unvalidated port in serialize
High
CVE-2026-84292
was published
for
fast-uri
(npm)
Sep 28, 2026
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
High
CVE-2026-84394
was published
for
fast-uri
(npm)
Sep 28, 2026
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)
Moderate
CVE-2026-83557
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Sep 28, 2026
ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
Moderate
CVE-2026-101913
was published
for
ip-address
(npm)
Sep 28, 2026
ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
Moderate
CVE-2026-101910
was published
for
ip-address
(npm)
Sep 28, 2026
Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements
High
CVE-2026-88058
was published
for
@angular/platform-server
(npm)
Sep 28, 2026
jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS
High
CVE-2026-68497
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Sep 28, 2026
jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution
Moderate
CVE-2026-19032
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Sep 28, 2026
jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization
Moderate
CVE-2026-77310
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Sep 28, 2026
@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
Moderate
CVE-2026-101914
was published
for
@grpc/grpc-js-xds
(npm)
Sep 28, 2026
scim-patch: Mutation of Inherited Built-in Method Objects
Moderate
CVE-2026-61834
was published
for
scim-patch
(npm)
Sep 28, 2026
code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)
High
GHSA-456v-xq2p-r4cj
was published
for
code-ollama
(npm)
Sep 28, 2026
SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests
High
CVE-2026-57443
was published
for
scbe-aethermoore
(pip)
Sep 25, 2026
mpp vulnerable to Gas Draining with low gas limit
High
GHSA-vj8p-hp9x-gh47
was published
for
mpp
(Erlang)
Sep 25, 2026
mpp vulnerable to Gas Draining with access list
Moderate
GHSA-qpxh-ff8m-c62v
was published
for
mpp
(Erlang)
Sep 25, 2026
mpp vulnerable to Gas Draining with no limit
High
GHSA-vv77-66rf-pm86
was published
for
mpp
(Erlang)
Sep 25, 2026
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
High
CVE-2026-100368
was published
for
AlastairLundy.CliInvoke.Specializations
(NuGet)
Sep 25, 2026
CliInvoke: Argument Injection in Extensibility Runner Factory
High
CVE-2026-100369
was published
for
AlastairLundy.CliInvoke
(NuGet)
Sep 25, 2026
khoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem
High
GHSA-62mm-xwmv-crhg
was published
for
khoj
(pip)
Sep 25, 2026
Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools
High
CVE-2026-86439
was published
for
knowns
(npm)
Sep 25, 2026
ProTip!
Advisories are also available from the
GraphQL API