GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
41
Go
3,100
Maven
5,000+
npm
4,993
NuGet
826
pip
4,425
Pub
12
RubyGems
988
Rust
1,170
Swift
50
Unreviewed advisories
All unreviewed
5,000+
26,831 advisories
Filter by severity
Flowise has Arbitrary File Upload via MIME Spoofing
High
CVE-2026-30821
was published
for
flowise
(npm)
Mar 6, 2026
Flowise has Authorization Bypass via Spoofed x-request-from Header
High
CVE-2026-30820
was published
for
flowise
(npm)
Mar 6, 2026
Mercurius's queryDepth limit bypassed for WebSocket subscriptions
Low
CVE-2026-30241
was published
for
mercurius
(npm)
Mar 6, 2026
parse-server's endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user
High
CVE-2026-30229
was published
for
parse-server
(npm)
Mar 6, 2026
parse-server's file creation and deletion bypasses `readOnlyMasterKey` write restriction
Moderate
CVE-2026-30228
was published
for
parse-server
(npm)
Mar 6, 2026
Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens
Moderate
GHSA-9r75-g2cr-3h76
was published
for
@workflow/core
(npm)
Mar 6, 2026
PinchTab has SSRF with Full Response Exfiltration via Download Handler
High
CVE-2026-30834
was published
for
github.com/pinchtab/pinchtab/cmd/pinchtab
(Go)
Mar 6, 2026
defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag
Low
CVE-2026-30830
was published
for
defuddle
(npm)
Mar 6, 2026
express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network
High
CVE-2026-30827
was published
for
express-rate-limit
(npm)
Mar 6, 2026
CoreDNS ACL Bypass
High
CVE-2026-26017
was published
for
github.com/coredns/coredns
(Go)
Mar 6, 2026
GitHub Copilot CLI Dangerous Shell Expansion Patterns Enable Arbitrary Code Execution
High
CVE-2026-29783
was published
for
@github/copilot
(npm)
Mar 6, 2026
SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality
High
GHSA-5r2p-pjr8-7fh7
was published
for
sagemaker
(pip)
Mar 5, 2026
Flowise Vulnerable to PII Disclosure on Unauthenticated Forgot Password Endpoint
Moderate
GHSA-jc5m-wrp2-qq38
was published
for
flowise
(npm)
Mar 5, 2026
Flowise has Insufficient Password Salt Rounds
Moderate
GHSA-x2g5-fvc2-gqvp
was published
for
flowise
(npm)
Mar 5, 2026
MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Injection and Email Forgery
Moderate
CVE-2026-30227
was published
for
MimeKit
(NuGet)
Mar 5, 2026
WeKnora is Vulnerable to SSRF via Redirection
Moderate
CVE-2026-30247
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 5, 2026
Plane is Vulnerable to Unauthenticated Workspace Member Information Disclosure
High
CVE-2026-30244
was published
for
plane
(pip)
Mar 5, 2026
Plane has SSRF via Incomplete IP Validation in Webhook URL Serializer
High
CVE-2026-30242
was published
for
plane
(pip)
Mar 5, 2026
mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint
Moderate
CVE-2026-29787
was published
for
mcp-memory-service
(pip)
Mar 5, 2026
org.eclipse.jetty:jetty-http has different parsing of invalid URIs
Low
CVE-2025-11143
was published
for
org.eclipse.jetty:jetty-http
(Maven)
Mar 5, 2026
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
Moderate
CVE-2026-3419
was published
for
fastify
(npm)
Mar 5, 2026
The Eclipse Jetty Server Artifact has a Gzip request memory leak
High
CVE-2026-1605
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Mar 5, 2026
OliveTin doesn't check view permission when returning dashboards
Moderate
CVE-2026-30233
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
`time-sync` was removed from crates.io due to malicious code
Critical
GHSA-mh23-rw7f-v5pq
was published
for
time-sync
(Rust)
Mar 5, 2026
EC-CUBE has a Vulnerability that Allows MFA Bypass in the Administrative Interface
Moderate
GHSA-7rhv-h82h-vpjh
was published
for
ec-cube/ec-cube
(Composer)
Mar 5, 2026
ProTip!
Advisories are also available from the
GraphQL API