GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
339,386 advisories
Filter by severity
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
High
CVE-2026-44890
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 8, 2026
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
High
CVE-2026-44250
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 8, 2026
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
High
CVE-2026-44249
was published
for
io.netty:netty-handler
(Maven)
Jun 8, 2026
FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
Moderate
CVE-2026-45802
was published
for
setasign/fpdi
(Composer)
May 19, 2026
MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration
Moderate
CVE-2026-47250
was published
for
mcp-server-kubernetes
(npm)
Jun 5, 2026
MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
High
CVE-2026-46519
was published
for
mcp-server-kubernetes
(npm)
May 21, 2026
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
High
CVE-2026-32936
was published
for
github.com/coredns/coredns
(Go)
Apr 28, 2026
aiograpi: Unsafe signup challenge path handling
Moderate
CVE-2026-47157
was published
for
aiograpi
(pip)
May 23, 2026
tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
High
CVE-2026-44705
was published
for
tmp
(npm)
May 27, 2026
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
High
CVE-2026-44495
was published
for
axios
(npm)
May 29, 2026
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
High
CVE-2026-44494
was published
for
axios
(npm)
May 29, 2026
axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
Moderate
CVE-2026-44490
was published
for
axios
(npm)
May 29, 2026
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
Low
CVE-2026-44489
was published
for
axios
(npm)
May 29, 2026
Allocation of Resources Without Limits or Throttling in Axios
High
CVE-2026-44488
was published
for
axios
(npm)
Jun 4, 2026
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
High
CVE-2026-44487
was published
for
axios
(npm)
Jun 4, 2026
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
High
CVE-2026-44486
was published
for
axios
(npm)
Jun 4, 2026
Bugsink: DOS using large numbers of event tags
Moderate
CVE-2026-53954
was published
for
bugsink
(pip)
Jun 5, 2026
NocoDB: OAuth Tokens Persist Through Security Events
Moderate
CVE-2026-53926
was published
for
nocodb
(npm)
Jun 5, 2026
guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator
Moderate
CVE-2026-53723
was published
for
guzzlehttp/guzzle-services
(Composer)
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
Moderate
CVE-2026-48998
was published
for
guzzlehttp/psr7
(Composer)
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
Moderate
CVE-2026-49214
was published
for
guzzlehttp/psr7
(Composer)
Jun 11, 2026
TYPO3 CMS has Broken Access Control in its Media Module
High
CVE-2026-49742
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Insecure Deserialization via Core API
Moderate
CVE-2026-49740
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its File Abstraction Layer
Low
CVE-2026-49738
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in Backend API
Moderate
CVE-2026-47352
was published
for
typo3/cms-backend
(Composer)
Jun 12, 2026
ProTip!
Advisories are also available from the
GraphQL API