GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
2,277 advisories
Filter by severity
esbuild allows arbitrary file read when running the development server on Windows
Low
GHSA-g7r4-m6w7-qqqr
was published
for
esbuild
(npm)
Jun 12, 2026
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
Low
CVE-2026-46342
was published
for
@nuxt/nitro-server
(npm)
May 19, 2026
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
Low
CVE-2026-44489
was published
for
axios
(npm)
May 29, 2026
TYPO3 CMS has Broken Access Control in its File Abstraction Layer
Low
CVE-2026-49738
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 HTML Sanitizer allows Cross-site Scripting
Low
CVE-2026-47344
was published
for
typo3/html-sanitizer
(Composer)
Jun 12, 2026
Tornado has out-of-bounds memory access via C extension
Low
CVE-2026-49854
was published
for
tornado
(pip)
Jun 12, 2026
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
Low
GHSA-6vgg-xhvh-38ff
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 12, 2026
SwiftNIO HTTP/2: HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec
Low
CVE-2026-28898
was published
for
github.com/apple/swift-nio-http2
(Swift)
Jun 12, 2026
Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
Low
CVE-2026-47712
was published
for
dulwich
(pip)
Jun 8, 2026
Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames
Low
CVE-2026-48011
was published
for
shopware/core
(Composer)
Jun 4, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
Low
CVE-2026-46668
was published
for
github.com/authzed/spicedb
(Go)
May 21, 2026
Crawlee for Python: SSRF via sitemap-derived URLs
Low
CVE-2026-46497
was published
for
crawlee
(pip)
May 21, 2026
PyTorch is vulnerable to memory corruption through its torch.lstm_cell function
Low
CVE-2025-3001
was published
for
torch
(pip)
Mar 31, 2025
PyTorch is vulnerable to memory corruption through its torch.jit.script function
Low
CVE-2025-3000
was published
for
torch
(pip)
Mar 31, 2025
sudo-rs Session File Relative Path Traversal vulnerability
Low
CVE-2023-42456
was published
for
sudo-rs
(Rust)
Sep 21, 2023
Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
Low
CVE-2026-48051
was published
for
@papra/webhooks
(npm)
Jun 10, 2026
PhoenixStorybook has cross-session PubSub topic injection via URL parameter
Low
CVE-2026-47068
was published
for
phoenix_storybook
(Erlang)
Jun 9, 2026
PyTorch: Manipulation of the argument scale/zero_point leads to improper initialization via Quantized Sigmoid Module
Low
CVE-2025-2149
was published
for
torch
(pip)
Mar 10, 2025
PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument
Low
CVE-2025-2148
was published
for
torch
(pip)
Mar 10, 2025
pywasm3 has Improper Restriction of Operations within the Bounds of a Memory Buffer
Low
CVE-2025-6272
was published
for
pywasm3
(pip)
Jun 19, 2025
Net::IMAP: Denial of Service via incomplete raw argument validation
Low
CVE-2026-47241
was published
for
net-imap
(RubyGems)
Jun 9, 2026
pretix has Email Content Injection Through Maliciously Formatted Names
Low
CVE-2025-13742
was published
for
pretix
(pip)
Nov 27, 2025
Nautobot missing object-level permissions enforcement when running Job Buttons
Low
CVE-2023-51649
was published
for
nautobot
(pip)
Dec 22, 2023
trailer mishandles allocating with a size of zero
Low
CVE-2025-47737
was published
for
trailer
(Rust)
May 9, 2025
OpenStack Keystone: Restricted application credentials can create EC2 credentials
Low
CVE-2026-33551
was published
for
keystone
(pip)
Apr 10, 2026
ProTip!
Advisories are also available from the
GraphQL API