GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,426
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,670
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,553 advisories
Filter by severity
Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
High
CVE-2026-34148
was published
for
@fedify/fedify
(npm)
Apr 7, 2026
Electron: Crash in clipboard.readImage() on malformed clipboard image data
Low
CVE-2026-34781
was published
for
electron
(npm)
Apr 7, 2026
Electron: Named window.open targets not scoped to the opener's browsing context
Moderate
CVE-2026-34765
was published
for
electron
(npm)
Apr 7, 2026
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
High
CVE-2026-34444
was published
for
lupa
(pip)
Apr 7, 2026
OpenIdentityPlatform OpenAM: Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM
Critical
CVE-2026-33439
was published
for
org.openidentityplatform.openam:openam
(Maven)
Apr 7, 2026
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
Moderate
CVE-2026-33866
was published
for
mlflow
(pip)
Apr 7, 2026
HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
Moderate
CVE-2026-1839
was published
for
transformers
(pip)
Apr 7, 2026
PraisonAI Has Path Traversal in FileTools
Critical
CVE-2026-35615
was published
for
PraisonAI
(pip)
Apr 6, 2026
PraisonAI recipe registry publish path traversal allows out-of-root file write
High
CVE-2026-39308
was published
for
PraisonAI
(pip)
Apr 6, 2026
PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
High
CVE-2026-39306
was published
for
PraisonAI
(pip)
Apr 6, 2026
PraisonAI Vulnerable to Arbitrary File Write / Path Traversal in Action Orchestrator
Critical
CVE-2026-39305
was published
for
PraisonAI
(pip)
Apr 6, 2026
PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
High
CVE-2026-39307
was published
for
PraisonAI
(pip)
Apr 6, 2026
go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers
Moderate
CVE-2026-35480
was published
for
github.com/ipld/go-ipld-prime
(Go)
Apr 6, 2026
PocketMine-MP: Player entities can still die and drop items in flaggedForDespawn state
Low
GHSA-f9jp-856v-8642
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 6, 2026
PocketMine-MP: Network amplification vulnerability with `ActorEventPacket`
Moderate
GHSA-7hmv-4j2j-pp6f
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 6, 2026
PocketMine-MP: JSON decoding of unlimited size large arrays/objects in ModalFormResponse Handling
High
GHSA-788v-5pfp-93ff
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 6, 2026
PocketMine-MP: LogDoS by large complex unknown property logging in clientData in LoginPacket
High
GHSA-h6rj-3m53-887h
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 6, 2026
OpenClaw's complex interpreter pipelines could skip exec script preflight validation
Moderate
CVE-2026-34425
was published
for
openclaw
(npm)
Apr 6, 2026
go.etcd.io/bbolt affected by index out-of-range vulnerability
Moderate
CVE-2026-33817
was published
for
go.etcd.io/bbolt
(Go)
Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation/editing module
Moderate
CVE-2026-31313
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation/editing module
Moderate
CVE-2026-31351
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Category module
Moderate
CVE-2026-31353
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Page Sign parameter
Moderate
CVE-2026-31350
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has authenticated stored cross-site scripting (XSS) vulnerabilities via the Permissions module
Moderate
CVE-2026-31354
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Role Management module
Moderate
CVE-2026-31352
was published
for
feehi/cms
(Composer)
Apr 6, 2026
ProTip!
Advisories are also available from the
GraphQL API