GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,815
Maven
5,000+
npm
4,428
NuGet
773
pip
4,203
Pub
12
RubyGems
968
Rust
1,088
Swift
47
Unreviewed advisories
All unreviewed
5,000+
25,358 advisories
Filter by severity
Mailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to emails
Moderate
CVE-2026-22689
was published
for
github.com/axllent/mailpit
(Go)
Jan 13, 2026
RustCrypto: Signatures has timing side-channel in ML-DSA decomposition
Moderate
CVE-2026-22705
was published
for
ml-dsa
(Rust)
Jan 13, 2026
HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover
High
CVE-2026-22704
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jan 13, 2026
RustCrypto Has Insufficient Length Validation in decrypt() in SM2-PKE
High
CVE-2026-22700
was published
for
sm2
(Rust)
Jan 13, 2026
Cosign verification accepts any valid Rekor entry under certain conditions
Moderate
CVE-2026-22703
was published
for
github.com/sigstore/cosign/v2
(Go)
Jan 13, 2026
n8n: Webhook Node IP Whitelist Bypass via Partial String Matching
Moderate
CVE-2025-68949
was published
for
n8n
(npm)
Jan 13, 2026
Jervis's AES CBC Mode is Without Authentication
High
CVE-2025-68931
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis Has a JWT Algorithm Confusion Vulnerability
Moderate
CVE-2025-68925
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis Has Weak Random for Timing Attack Mitigation
High
CVE-2025-68704
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis's Salt for PBKDF2 derived from password
High
CVE-2025-68703
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis Has a SHA-256 Hex String Padding Bug
High
CVE-2025-68702
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis has Deterministic AES IV Derivation from Passphrase
High
CVE-2025-68701
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis Has a RSA PKCS#1 Padding Vulnerability
High
CVE-2025-68698
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Weblate wlc has insecure API key configuration
Moderate
CVE-2026-22251
was published
for
wlc
(pip)
Jan 12, 2026
Weblate command-line client susceptible to SSL verification skip
Low
CVE-2026-22250
was published
for
wlc
(pip)
Jan 12, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
High
CVE-2026-22033
was published
for
label-studio
(pip)
Jan 12, 2026
MindsDB has improper sanitation of filepath that leads to information disclosure and DOS
High
CVE-2025-68472
was published
for
MindsDB
(pip)
Jan 12, 2026
SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt()
High
CVE-2026-22699
was published
for
sm2
(Rust)
Jan 9, 2026
Fickling vulnerable to detection bypass due to "builtins" blindness
High
CVE-2026-22612
was published
for
fickling
(pip)
Jan 9, 2026
SM2-PKE has 32-bit Biased Nonce Vulnerability
High
CVE-2026-22698
was published
for
sm2
(Rust)
Jan 9, 2026
Shiori is vulnerable to authentication bypass via a brute force attack
Moderate
CVE-2025-60538
was published
for
github.com/go-shiori/shiori
(Go)
Jan 9, 2026
Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
High
CVE-2026-22609
was published
for
fickling
(pip)
Jan 9, 2026
Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
High
CVE-2026-22608
was published
for
fickling
(pip)
Jan 9, 2026
Fickling Blocklist Bypass: cProfile.run()
High
CVE-2026-22607
was published
for
fickling
(pip)
Jan 9, 2026
Fickling has a bypass via runpy.run_path() and runpy.run_module()
High
CVE-2026-22606
was published
for
fickling
(pip)
Jan 9, 2026
ProTip!
Advisories are also available from the
GraphQL API