GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
2,277 advisories
Filter by severity
Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields
Low
CVE-2026-4053
was published
for
github.com/mattermost/mattermost-server
(Go)
May 15, 2026
Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
Low
CVE-2026-45316
was published
for
open-webui
(pip)
May 14, 2026
dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction
Low
CVE-2026-44970
was published
for
dbt-mcp
(pip)
May 14, 2026
dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
Low
CVE-2026-44969
was published
for
dbt-mcp
(pip)
May 14, 2026
Strapi: Password Reset Does Not Revoke Existing Refresh Sessions
Low
CVE-2026-22706
was published
for
@strapi/admin
(npm)
May 13, 2026
Astro: Server island encrypted parameters vulnerable to cross-component replay
Low
CVE-2026-45028
was published
for
astro
(npm)
May 13, 2026
Apache Tomcat - AJP secret compared in non-constant time
Low
CVE-2026-43514
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 12, 2026
omec-project amf crashes when processing malformed LocationReports
Low
CVE-2026-8349
was published
for
github.com/omec-project/amf
(Go)
May 12, 2026
cowlib: Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
Low
CVE-2026-43969
was published
for
cowlib
(Erlang)
May 11, 2026
Duplicate Advisory: OpenClaw's ACP child sessions inherit subagent security envelope constraints
Low
GHSA-w626-296m-8f85
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners
Low
GHSA-p3pv-c954-9m6f
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Next.js's Middleware / Proxy redirects can be cache-poisoned
Low
CVE-2026-44572
was published
for
next
(npm)
May 11, 2026
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
Low
CVE-2026-44582
was published
for
next
(npm)
May 11, 2026
Ella Core has handover failures during concurrent Security Mode Command
Low
CVE-2026-44474
was published
for
github.com/ellanetworks/core
(Go)
May 11, 2026
bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go
Low
CVE-2026-8276
was published
for
github.com/bettercap/bettercap/v2
(Go)
May 11, 2026
bettercap Has an Integer Coercion Error in the ippReadChunkedBody Function
Low
CVE-2026-8275
was published
for
github.com/bettercap/bettercap/v2
(Go)
May 11, 2026
OSGeo gdal has a heap-based buffer overflow
Low
CVE-2026-8212
was published
for
GDAL
(pip)
May 10, 2026
Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
Low
CVE-2026-44459
was published
for
hono
(npm)
May 9, 2026
absinthe_plug Has a Cross-site Scripting vulnerability
Low
CVE-2026-42794
was published
for
absinthe_plug
(Erlang)
May 8, 2026
justhtml introduces denial-of-service hardening
Low
GHSA-r8cj-3554-33mr
was published
for
justhtml
(pip)
May 8, 2026
nhost has Session Persistence After Password Change
Low
GHSA-7hgr-xvrr-xpw3
was published
for
github.com/nhost/nhost
(Go)
May 8, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience
Low
CVE-2026-44428
was published
for
github.com/modelcontextprotocol/registry
(Go)
May 8, 2026
OSGeo GDAL vulnerable to out-of-bounds read
Low
CVE-2026-8088
was published
for
GDAL
(pip)
May 7, 2026
OSGeo GDAL vulnerable to heap-based buffer overflow
Low
CVE-2026-8087
was published
for
GDAL
(pip)
May 7, 2026
Webauthn has a User Verification Downgrade via Default-Open ClientOverridePolicy
Low
GHSA-h4fw-6r7f-w494
was published
for
web-auth/webauthn-framework
(Composer)
May 7, 2026
ProTip!
Advisories are also available from the
GraphQL API