GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
6,648 advisories
Filter by severity
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing
Moderate
GHSA-vc8p-8pxg-rfwg
was published
for
org.connectbot.sshlib:sshlib
(Maven)
Jun 12, 2026
ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation
Moderate
GHSA-ch3q-cw5r-f4hg
was published
for
org.connectbot.sshlib:sshlib
(Maven)
Jun 12, 2026
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
High
GHSA-j9gf-vw2f-9hrw
was published
for
com.appsmith:server
(Maven)
Jun 12, 2026
Appsmith Super User Creation Race Condition Allows Multiple Instance Administrators
High
GHSA-9wcp-79g5-5c3c
was published
for
com.appsmith:server
(Maven)
Jun 12, 2026
GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
Moderate
CVE-2025-58175
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 12, 2026
GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
High
CVE-2025-52465
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 12, 2026
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
High
CVE-2025-27511
was published
for
org.geoserver.extension:gs-db2
(Maven)
Jun 11, 2026
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
High
CVE-2026-48059
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jun 11, 2026
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
Moderate
CVE-2026-48043
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 11, 2026
netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
Moderate
CVE-2026-48040
was published
for
io.netty.incubator:netty-incubator-codec-ohttp-hpke-native-boringssl
(Maven)
Jun 11, 2026
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
High
CVE-2026-48006
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 11, 2026
Acknowledgement extension out of memory
High
CVE-2025-53114
was published
for
org.cometd.java:cometd-java-server-common
(Maven)
Jun 10, 2026
Jenkins: Stored XSS vulnerability in node offline cause description
High
CVE-2026-53441
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
High
CVE-2026-41731
was published
for
org.springframework.kafka:spring-kafka
(Maven)
Jun 10, 2026
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
Moderate
CVE-2026-41726
was published
for
org.springframework.kafka:spring-kafka
(Maven)
Jun 10, 2026
Netty has Insufficient Bailiwick Validation for NS Records
High
CVE-2026-47691
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
Moderate
CVE-2026-47244
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 8, 2026
Netty: SCTP reassembly nests buffers without bound
High
CVE-2026-46340
was published
for
io.netty:netty-transport-sctp
(Maven)
Jun 8, 2026
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
High
CVE-2026-45674
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
Moderate
CVE-2026-45673
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
Netty: Unix-socket fd receive leaks descriptors when peer sends two at once
Moderate
CVE-2026-45536
was published
for
io.netty:netty-transport-native-epoll
(Maven)
Jun 8, 2026
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
High
CVE-2026-45416
was published
for
io.netty:netty-handler
(Maven)
Jun 8, 2026
Netty's Default QUIC token handler accepts any client-supplied token
High
CVE-2026-44894
was published
for
io.netty:netty-codec-classes-quic
(Maven)
Jun 8, 2026
Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
High
CVE-2026-44893
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jun 8, 2026
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
High
CVE-2026-44892
was published
for
io.netty:netty-codec-http3
(Maven)
Jun 8, 2026
ProTip!
Advisories are also available from the
GraphQL API