GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
117
GitHub Actions
55
Go
4,830
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,155
Rust
1,577
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
35,868 advisories
Filter by severity
Solspace Freeform: Limited Twig template injection via submitted field values
Moderate
CVE-2026-73858
was published
for
solspace/craft-freeform
(Composer)
Sep 23, 2026
WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost
Moderate
CVE-2026-88974
was published
for
wp-graphql/wp-graphql
(Composer)
Sep 23, 2026
REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates
Moderate
CVE-2026-63000
was published
for
redaxo/source
(Composer)
Sep 23, 2026
REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames
Moderate
CVE-2026-63002
was published
for
redaxo/source
(Composer)
Sep 23, 2026
REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`
Moderate
CVE-2026-63001
was published
for
redaxo/source
(Composer)
Sep 23, 2026
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
High
CVE-2026-54892
was published
for
plug
(Erlang)
Sep 23, 2026
Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service
Moderate
CVE-2026-61541
was published
for
zapros
(pip)
Sep 23, 2026
Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)
High
CVE-2026-61652
was published
for
zapros
(pip)
Sep 23, 2026
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
Critical
CVE-2026-57149
was published
for
plone.app.portlets
(pip)
Sep 23, 2026
Home Assistant: XSS in Statistics Graph Card
Critical
CVE-2026-91130
was published
for
homeassistant
(pip)
Sep 22, 2026
Home Assistant: mDNS Server-Side Request Forgery
Moderate
CVE-2026-91129
was published
for
homeassistant
(pip)
Sep 22, 2026
Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle
Moderate
CVE-2026-88010
was published
for
Traefik
(Go)
Sep 22, 2026
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter
Moderate
CVE-2026-88978
was published
for
github.com/hatchet-dev/hatchet
(Go)
Sep 22, 2026
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher
Low
CVE-2026-84298
was published
for
github.com/hatchet-dev/hatchet
(Go)
Sep 22, 2026
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
Moderate
CVE-2026-79913
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
Gardener: Authorization Bypass via Group Subject Injection
Moderate
CVE-2026-79767
was published
for
gardener/gardener
(Go)
Sep 22, 2026
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope
Low
CVE-2026-77637
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
High
CVE-2026-77633
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
High
CVE-2026-94462
was published
for
spree_api
(RubyGems)
Sep 22, 2026
lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content
Moderate
CVE-2026-86062
was published
for
lightrag-hku
(pip)
Sep 22, 2026
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
High
CVE-2026-85740
was published
for
lightrag-hku
(pip)
Sep 22, 2026
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
Critical
CVE-2026-85734
was published
for
lightrag-hku
(pip)
Sep 22, 2026
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function
Moderate
CVE-2026-85725
was published
for
lightrag-hku
(pip)
Sep 22, 2026
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
Moderate
CVE-2026-85709
was published
for
lightrag-hku
(pip)
Sep 22, 2026
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
Moderate
CVE-2026-83805
was published
for
nautobot
(pip)
Sep 22, 2026
ProTip!
Advisories are also available from the
GraphQL API