GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,951
Maven
5,000+
npm
4,598
NuGet
787
pip
4,305
Pub
12
RubyGems
983
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
25,955 advisories
Filter by severity
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
Moderate
CVE-2026-25765
was published
for
faraday
(RubyGems)
Feb 9, 2026
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
Moderate
CVE-2026-25528
was published
for
langsmith
(npm)
Feb 9, 2026
Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
High
CVE-2026-25498
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS: GraphQL Asset Mutation Privilege Escalation
High
CVE-2026-25497
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to Stored XSS in Number Prefix & Suffix Fields
Moderate
CVE-2026-25496
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`
High
CVE-2026-25495
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via Alternative IP Notation
Moderate
CVE-2026-25494
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via HTTP Redirect
Moderate
CVE-2026-25493
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS: save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying host
Moderate
CVE-2026-25492
was published
for
craftcms/craft
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to Stored XSS in Entry Types Name
Low
CVE-2026-25491
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Super-linter is vulnerable to command injection via crafted filenames in Super-linter Action
High
CVE-2026-25761
was published
for
super-linter/super-linter
(GitHub Actions)
Feb 9, 2026
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
High
CVE-2026-25639
was published
for
axios
(npm)
Feb 9, 2026
Harden-Runner: Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)
Moderate
CVE-2026-25598
was published
for
step-security/harden-runner
(GitHub Actions)
Feb 9, 2026
Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
Moderate
CVE-2026-25480
was published
for
litestar
(pip)
Feb 9, 2026
Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns
Moderate
CVE-2026-25479
was published
for
litestar
(pip)
Feb 9, 2026
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
High
CVE-2026-25478
was published
for
litestar
(pip)
Feb 9, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure
Critical
CVE-2025-66630
was published
for
github.com/gofiber/fiber/v2
(Go)
Feb 9, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service
High
CVE-2026-25791
was published
for
github.com/bishopfox/sliver
(Go)
Feb 6, 2026
Antrea has invalid enforcement order for network policy rules caused by integer overflow
High
CVE-2026-25804
was published
for
antrea.io/antrea
(Go)
Feb 6, 2026
Keylime Missing Authentication for Critical Function and Improper Authentication
Critical
CVE-2026-1709
was published
for
keylime
(pip)
Feb 6, 2026
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic
Low
GHSA-vhvq-fv9f-wh4q
was published
for
github.com/authzed/spicedb
(Go)
Feb 6, 2026
Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper Authentication
Critical
GHSA-27jc-jmp8-qfw5
was published
for
keylime
(pip)
Feb 6, 2026
•
withdrawn
`uniswap-utils` was removed from crates.io for malicious code
Critical
GHSA-x468-phr8-h3p3
was published
for
uniswap-utils
(Rust)
Feb 6, 2026
`sha-rust` was removed from crates.io for malicious code
Critical
GHSA-3mmg-7c2q-8938
was published
for
sha-rust
(Rust)
Feb 6, 2026
`finch-rust` was removed from crates.io for malicious code
Critical
GHSA-f8h5-x737-x4xr
was published
for
finch-rust
(Rust)
Feb 6, 2026
ProTip!
Advisories are also available from the
GraphQL API