GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
912
pip
4,768
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
Hono vulnerable to arbitrary file access via serveStatic vulnerability
High
CVE-2026-29045
was published
for
hono
(npm)
Mar 4, 2026
@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)
High
CVE-2026-22037
was published
for
@fastify/express
(npm)
Jan 20, 2026
Fastify Middie Middleware Path Bypass
High
CVE-2026-22031
was published
for
@fastify/middie
(npm)
Jan 20, 2026
Apache Linkis: Arbitrary File Read via Double URL Encoding Bypass
High
CVE-2025-29847
was published
for
org.apache.linkis:linkis
(Maven)
Jan 19, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and...
Low
Unreviewed
CVE-2025-11990
was published
Nov 15, 2025
An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect...
Low
Unreviewed
CVE-2024-48866
was published
Dec 6, 2024
Improper handling of canonical URL-encoding may lead to bypass not properly constrained by...
Moderate
Unreviewed
CVE-2024-23983
was published
Nov 12, 2024
Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
Moderate
CVE-2023-47106
was published
for
github.com/traefik/traefik/v2
(Go)
Dec 5, 2023
A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit...
Moderate
Unreviewed
CVE-2022-3854
was published
Mar 7, 2023
Keycloak vulnerable to path traversal via double URL encoding
Critical
CVE-2022-3782
was published
for
org.keycloak:keycloak-parent
(Maven)
Dec 13, 2022
The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host...
High
Unreviewed
CVE-2022-27780
was published
Jun 3, 2022
vercel/serve allows access to restricted files if filename is URL encoded.
Moderate
CVE-2018-3718
was published
for
serve
(npm)
Aug 9, 2021
Path Traversal in superstatic
High
GHSA-wm77-q74p-5763
was published
for
superstatic
(npm)
Jul 27, 2018
ProTip!
Advisories are also available from the
GraphQL API