GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,742
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
35,550 advisories
Filter by severity
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
Critical
CVE-2026-59178
was published
for
esphome-device-builder
(pip)
Sep 14, 2026
October CMS: Incomplete Scheme Validation in Image Resizer
Low
GHSA-2xmm-m4wv-3fjh
was published
for
october/october
(Composer)
Sep 14, 2026
October CMS: PHP Object Injection via Backend Widget Session Storage
Low
CVE-2026-49400
was published
for
october/system
(Composer)
Sep 14, 2026
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
Low
CVE-2026-46696
was published
for
october/system
(Composer)
Sep 14, 2026
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
Moderate
CVE-2026-56666
was published
for
github.com/zitadel/zitadel
(Go)
Sep 11, 2026
yayson: Prototype pollution in Store/LegacyStore deserialization
Critical
CVE-2026-61534
was published
for
yayson
(npm)
Sep 11, 2026
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
High
CVE-2026-59148
was published
for
@mockoon/cli
(npm)
Sep 11, 2026
@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
Moderate
CVE-2026-59149
was published
for
@mockoon/cli
(npm)
Sep 11, 2026
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
High
CVE-2026-59973
was published
for
@frontmcp/adapters
(npm)
Sep 11, 2026
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
Critical
CVE-2026-59151
was published
for
prowler-cloud
(pip)
Sep 11, 2026
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
Moderate
CVE-2026-56665
was published
for
github.com/zitadel/zitadel
(Go)
Sep 11, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
High
CVE-2026-56825
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
Moderate
CVE-2026-56830
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
High
CVE-2026-56829
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: privilege escalation via improper Livewire admin component authorization
High
CVE-2026-56828
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
Moderate
CVE-2026-56826
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
Moderate
CVE-2026-56831
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
High
CVE-2026-56827
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)
High
CVE-2026-11745
was published
for
com.linecorp.centraldogma:centraldogma-server-mirror-git
(Maven)
Sep 11, 2026
Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover
Critical
CVE-2026-11746
was published
for
com.linecorp.centraldogma:centraldogma-server
(Maven)
Sep 11, 2026
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion
Moderate
CVE-2026-11748
was published
for
com.linecorp.centraldogma:centraldogma-server-auth-shiro
(Maven)
Sep 11, 2026
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
Critical
CVE-2026-59971
was published
for
mysql-mcp-server
(pip)
Sep 11, 2026
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
Moderate
CVE-2026-88006
was published
for
open-webui
(pip)
Sep 10, 2026
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
High
CVE-2026-88008
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
Traefik entrypoint header-name sanitization bypassed via request trailers
High
CVE-2026-88004
was published
for
github.com/traefik/traefik/v3
(Go)
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API