GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,436
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,694
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,615 advisories
Filter by severity
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
Moderate
CVE-2026-39390
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
Moderate
CVE-2026-39389
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper class
Moderate
GHSA-jx2w-vp7f-456q
was published
for
io.quarkiverse.openapi.generator:quarkus-openapi-generator
(Maven)
Apr 8, 2026
stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution
High
CVE-2026-31040
was published
for
stata-mcp
(pip)
Apr 8, 2026
Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit
High
CVE-2026-27806
was published
for
github.com/fleetdm/fleet/v4
(Go)
Apr 8, 2026
Axios HTTP/2 Session Cleanup State Corruption Vulnerability
Moderate
CVE-2026-39865
was published
for
axios
(npm)
Apr 8, 2026
pretix: API leaks check-in data between events of the same organizer
Moderate
CVE-2026-5600
was published
for
pretix
(pip)
Apr 8, 2026
Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
High
CVE-2026-5795
was published
for
org.eclipse.jetty.ee10:jetty-ee10
(Maven)
Apr 8, 2026
OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write
High
CVE-2026-34589
was published
for
OpenEXR
(pip)
Apr 8, 2026
OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
High
CVE-2026-34588
was published
for
OpenEXR
(pip)
Apr 8, 2026
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
Moderate
GHSA-vvjj-xcjg-gr5g
was published
for
nodemailer
(npm)
Apr 8, 2026
kubernetes-graphql-gateway: GraphQL Endpoint Vulnerable to Authenticated Denial-of-Service via Unrestricted Query Execution
Moderate
GHSA-h9mw-h4qc-f5jf
was published
for
github.com/platform-mesh/kubernetes-graphql-gateway
(Go)
Apr 8, 2026
LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read
Moderate
CVE-2026-39859
was published
for
liquidjs
(npm)
Apr 8, 2026
LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel
Moderate
CVE-2026-39412
was published
for
liquidjs
(npm)
Apr 8, 2026
LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header
Moderate
CVE-2026-39411
was published
for
@lobehub/lobehub
(npm)
Apr 8, 2026
kcp's cache server is accessible without authentication or authorization checks
High
CVE-2026-39429
was published
for
github.com/kcp-dev/kcp
(Go)
Apr 8, 2026
NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows
Moderate
CVE-2026-39844
was published
for
nicegui
(pip)
Apr 8, 2026
SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table captions
Critical
CVE-2026-39846
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 8, 2026
LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates
High
CVE-2026-35525
was published
for
liquidjs
(npm)
Apr 8, 2026
LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
Low
CVE-2026-34166
was published
for
liquidjs
(npm)
Apr 8, 2026
rfc3161-client Has Improper Certificate Validation
Moderate
CVE-2026-33753
was published
for
rfc3161-client
(pip)
Apr 8, 2026
XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting API
High
CVE-2026-33229
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Apr 8, 2026
parisneo/lollms has an insufficient session expiration vulnerability
Moderate
CVE-2026-1163
was published
for
lollms
(pip)
Apr 8, 2026
Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
Moderate
GHSA-xmrv-pmrh-hhx2
was published
for
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
(Go)
Apr 8, 2026
Emmett has a path traversal in internal assets handler
Critical
CVE-2026-39847
was published
for
emmett
(pip)
Apr 8, 2026
ProTip!
Advisories are also available from the
GraphQL API