GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,470
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,143
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34,062 advisories
Filter by severity
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
Critical
CVE-2026-52887
was published
for
@nocobase/plugin-notification-in-app-message
(npm)
Jul 31, 2026
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
High
CVE-2026-53599
was published
for
redaxo/source
(Composer)
Jul 31, 2026
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
Moderate
CVE-2026-53466
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 31, 2026
Savon::Model evaluates WSDL operation names as Ruby source
High
CVE-2026-53510
was published
for
savon
(RubyGems)
Jul 31, 2026
Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
Moderate
CVE-2026-65841
was published
for
jodit
(npm)
Jul 31, 2026
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
High
CVE-2026-58263
was published
for
jodit
(npm)
Jul 31, 2026
Jodit has prototype pollution via Jodit.configure() / ConfigMerge
Moderate
CVE-2026-54756
was published
for
jodit
(npm)
Jul 31, 2026
Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
Moderate
CVE-2026-62324
was published
for
jodit
(npm)
Jul 31, 2026
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
High
CVE-2026-53502
was published
for
thumbor
(pip)
Jul 31, 2026
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
High
CVE-2026-53505
was published
for
thumbor
(pip)
Jul 31, 2026
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
High
CVE-2026-53504
was published
for
thumbor
(pip)
Jul 31, 2026
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
High
CVE-2026-53503
was published
for
thumbor
(pip)
Jul 31, 2026
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
High
CVE-2026-53501
was published
for
thumbor
(pip)
Jul 31, 2026
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
High
CVE-2026-53500
was published
for
thumbor
(pip)
Jul 31, 2026
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
High
CVE-2026-54737
was published
for
@phun-ky/defaults-deep
(npm)
Jul 31, 2026
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
Critical
CVE-2026-54725
was published
for
github.com/bank-vaults/vault-secrets-webhook
(Go)
Jul 31, 2026
hashi-vault-js has a path traversal and query parameter injection
High
CVE-2026-55100
was published
for
hashi-vault-js
(npm)
Jul 31, 2026
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
High
CVE-2026-54729
was published
for
dssrf
(npm)
Jul 31, 2026
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
Moderate
CVE-2026-65835
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Moderate
CVE-2026-65834
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)
Moderate
CVE-2026-67550
was published
for
re2
(npm)
Jul 31, 2026
re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)
Moderate
CVE-2026-68499
was published
for
re2
(npm)
Jul 31, 2026
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
Moderate
CVE-2026-68501
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
High
CVE-2026-68500
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
High
CVE-2026-56819
was published
for
io.netty:netty-codec-http2
(Maven)
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API