GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,883
Maven
5,000+
npm
4,522
NuGet
785
pip
4,262
Pub
12
RubyGems
975
Rust
1,105
Swift
49
Unreviewed advisories
All unreviewed
5,000+
11,388 advisories
Filter by severity
PsySH has Local Privilege Escalation via CWD .psysh.php auto-load
Moderate
CVE-2026-25129
was published
for
psy/psysh
(Composer)
Jan 30, 2026
Umbraco.Forms has Path Traversal and File Enumeration Vulnerabilities in Linux/Mac
Moderate
CVE-2026-24687
was published
for
Umbraco.Forms
(NuGet)
Jan 30, 2026
malcontent vulnerable to symlink Path Traversal via handleSymlink argument confusion in archive extraction
Moderate
CVE-2026-24846
was published
for
github.com/chainguard-dev/malcontent
(Go)
Jan 29, 2026
malcontent OCI image pull credential exfiltration via malicious registry token realm
Moderate
CVE-2026-24845
was published
for
github.com/chainguard-dev/malcontent
(Go)
Jan 29, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
Moderate
GHSA-h5qv-qjv4-pc5m
was published
for
dfir-unfurl
(pip)
Jan 29, 2026
Maker.js has Unsafe Property Copying in makerjs.extendObject
Moderate
CVE-2026-24888
was published
for
makerjs
(npm)
Jan 29, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
Moderate
CVE-2026-24889
was published
for
soroban-sdk
(Rust)
Jan 28, 2026
NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS
Moderate
CVE-2026-24766
was published
for
nocodb
(npm)
Jan 28, 2026
NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality
Moderate
CVE-2026-24767
was published
for
nocodb
(npm)
Jan 28, 2026
NocoDB has Unvalidated Redirect in Login Flow via continueAfterSignIn Parameter
Moderate
CVE-2026-24768
was published
for
nocodb
(npm)
Jan 28, 2026
Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows
Moderate
CVE-2026-24739
was published
for
symfony/process
(Composer)
Jan 28, 2026
BrowserStack Local vulnerable to Command Injection through logfile variable
Moderate
CVE-2025-57283
was published
for
browserstack-local
(npm)
Jan 28, 2026
ML-DSA Signature Verification Accepts Signatures with Repeated Hint Indices
Moderate
CVE-2026-24850
was published
for
ml-dsa
(Rust)
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
Moderate
CVE-2026-24784
was published
for
DotNetNuke.Core
(NuGet)
Jan 28, 2026
Hono vulnerable to XSS through ErrorBoundary component
Moderate
CVE-2026-24771
was published
for
hono
(npm)
Jan 28, 2026
TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery (SSRF)
Moderate
GHSA-gpx9-96j6-pp87
was published
for
agentos-taskweaver
(pip)
Jan 28, 2026
Next.js has Unbounded Memory Consumption via PPR Resume Endpoint
Moderate
CVE-2025-59472
was published
for
next
(npm)
Jan 28, 2026
vlt Mishandles Path Sanitization for tar
Moderate
CVE-2026-24909
was published
for
@vltpkg/tar
(npm)
Jan 28, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access
Moderate
CVE-2026-24748
was published
for
github.com/akuity/kargo
(Go)
Jan 27, 2026
StudioCMS has Authorization Bypass Through User-Controlled Key
Moderate
CVE-2026-24134
was published
for
studiocms
(npm)
Jan 27, 2026
Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
Moderate
CVE-2025-59471
was published
for
next
(npm)
Jan 27, 2026
Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)
Moderate
CVE-2026-24473
was published
for
hono
(npm)
Jan 27, 2026
Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception
Moderate
CVE-2026-24472
was published
for
hono
(npm)
Jan 27, 2026
Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing
Moderate
CVE-2026-24398
was published
for
hono
(npm)
Jan 27, 2026
OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication
Moderate
CVE-2026-23892
was published
for
OctoPrint
(pip)
Jan 27, 2026
ProTip!
Advisories are also available from the
GraphQL API