GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
895 advisories
Filter by severity
Apache Polaris has an Improper Input Validation Issue
Critical
CVE-2026-42810
was published
for
org.apache.polaris:polaris-core
(Maven)
May 4, 2026
Apache Polaris has an Improper Input Validation Issue
Critical
CVE-2026-42809
was published
for
org.apache.polaris:polaris-runtime-service
(Maven)
May 4, 2026
Apache Polaris has an Improper Input Validation issue
Critical
CVE-2026-42812
was published
for
org.apache.polaris:polaris-runtime-service
(Maven)
May 4, 2026
Apache Polaris has an Improper Input Validation issue
Critical
CVE-2026-42811
was published
for
org.apache.polaris:polaris-core
(Maven)
May 4, 2026
Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing
Critical
CVE-2026-40682
was published
for
org.apache.opennlp:opennlp-tools
(Maven)
May 4, 2026
OpenMRS Module Upload Vulnerable to Path Traversal (Zip Slip)
Critical
CVE-2026-40076
was published
for
org.openmrs.web:openmrs-web
(Maven)
May 4, 2026
Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41635 Incomplete Fix)
Critical
CVE-2026-42779
was published
for
org.apache.mina:mina-core
(Maven)
May 1, 2026
Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)
Critical
CVE-2026-42778
was published
for
org.apache.mina:mina-core
(Maven)
May 1, 2026
Shopizer has a path traversal issue
Critical
CVE-2026-36767
was published
for
com.shopizer:shopizer
(Maven)
Apr 30, 2026
fabric-sdk-java has ObjectInputStream.readObject() without ObjectInputFilter, which allows Java deserialization RCE
Critical
CVE-2026-41586
was published
for
org.hyperledger.fabric-sdk-java:fabric-sdk-java
(Maven)
Apr 29, 2026
Jenkins GitHub Plugin has an XSS vulnerability
Critical
CVE-2026-42523
was published
for
org.jenkins-ci.plugins:git
(Maven)
Apr 29, 2026
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
Critical
CVE-2026-40976
was published
for
org.springframework.boot:spring-boot
(Maven)
Apr 28, 2026
Apache Camel's Camel-Mail component is vulnerable to Camel message header injection
Critical
CVE-2026-33454
was published
for
org.apache.camel:camel-mail
(Maven)
Apr 27, 2026
Apache camel-coap allows header injection that can lead to remote code execution
Critical
CVE-2026-33453
was published
for
org.apache.camel:camel-coap
(Maven)
Apr 27, 2026
Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)
Critical
CVE-2026-41409
was published
for
org.apache.mina:mina-core
(Maven)
Apr 27, 2026
Apache MINA vulnerable to Deserialization of Untrusted Data
Critical
CVE-2026-41635
was published
for
org.apache.mina:mina-core
(Maven)
Apr 27, 2026
Apache Camel has an incomplete fix for CVE-2025-27636
Critical
CVE-2026-40453
was published
for
org.apache.camel:camel-coap
(Maven)
Apr 27, 2026
Spinnaker: RCE via expression parsing due to unrestricted context handling
Critical
CVE-2026-32613
was published
for
io.spinnaker.echo:echo-pipelinetriggers
(Maven)
Apr 21, 2026
Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
Critical
CVE-2026-32604
was published
for
io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo
(Maven)
Apr 21, 2026
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
Critical
CVE-2026-33557
was published
for
org.apache.kafka:kafka-clients
(Maven)
Apr 20, 2026
Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
Critical
CVE-2026-40478
was published
for
org.thymeleaf:thymeleaf
(Maven)
Apr 15, 2026
Improper restriction of the scope of accessible objects in Thymeleaf expressions
Critical
CVE-2026-40477
was published
for
org.thymeleaf:thymeleaf
(Maven)
Apr 15, 2026
Expression Injection in OpenRemote
Critical
CVE-2026-39842
was published
for
io.openremote:openremote-manager
(Maven)
Apr 14, 2026
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
Critical
CVE-2026-29145
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 9, 2026
Emissary has GitHub Actions Shell Injection via Workflow Inputs
Critical
CVE-2026-35580
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 8, 2026
ProTip!
Advisories are also available from the
GraphQL API