GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,426
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,670
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,553 advisories
Filter by severity
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
Moderate
CVE-2026-39365
was published
for
vite
(npm)
Apr 6, 2026
Vite: `server.fs.deny` bypassed with queries
High
CVE-2026-39364
was published
for
vite
(npm)
Apr 6, 2026
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
High
CVE-2026-39363
was published
for
vite
(npm)
Apr 6, 2026
strawberry-graphql: Denial of Service via unbounded WebSocket subscriptions
High
CVE-2026-35526
was published
for
strawberry-graphql
(pip)
Apr 6, 2026
strawberry-graphql: Authentication bypass via legacy graphql-ws WebSocket subprotocol
High
CVE-2026-35523
was published
for
strawberry-graphql
(pip)
Apr 6, 2026
changedetection.io Vulnerable to Authentication Bypass via Decorator Ordering
Critical
CVE-2026-35490
was published
for
changedetection.io
(pip)
Apr 6, 2026
@nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')
Moderate
CVE-2026-35515
was published
for
@nestjs/core
(npm)
Apr 6, 2026
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri
High
GHSA-x3f4-v83f-7wp2
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
Authorizer: CQL/N1QL Injection in Cassandra and Couchbase Backends via fmt.Sprintf String Interpolation
High
GHSA-jfwg-rxf3-p7r9
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
Moderate
CVE-2026-35492
was published
for
kedro-datasets
(pip)
Apr 6, 2026
rdiscount has an Out-of-bounds Read
Moderate
CVE-2026-35201
was published
for
rdiscount
(RubyGems)
Apr 6, 2026
Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation
High
CVE-2026-35172
was published
for
github.com/distribution/distribution
(Go)
Apr 6, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
Critical
CVE-2026-35035
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 6, 2026
Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm
High
CVE-2026-33540
was published
for
github.com/distribution/distribution
(Go)
Apr 6, 2026
OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp
Moderate
CVE-2026-26981
was published
for
OpenEXR
(pip)
Apr 6, 2026
OpenEXR has use after free in PyObject_StealAttrString
Moderate
CVE-2025-64183
was published
for
OpenEXR
(pip)
Apr 6, 2026
OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()
Moderate
CVE-2025-64182
was published
for
OpenEXR
(pip)
Apr 6, 2026
OpenEXR Makes Use of Uninitialized Memory
Low
CVE-2025-64181
was published
for
OpenEXR
(pip)
Apr 6, 2026
Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim
Low
CVE-2026-37977
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 6, 2026
@nor2/heim-mcp vulnerable to command injection
Low
CVE-2026-5602
was published
for
@nor2/heim-mcp
(npm)
Apr 6, 2026
@elgentos/magento2-dev-mcp vulnerable to command injection
Low
CVE-2026-5603
was published
for
@elgentos/magento2-dev-mcp
(npm)
Apr 6, 2026
PyBlade: SSTI/RCE via Bypassed AST Validation in sandbox.py
Low
CVE-2026-5559
was published
for
pyblade
(pip)
Apr 5, 2026
pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)
High
CVE-2026-35464
was published
for
pyload-ng
(pip)
Apr 4, 2026
pyLoad: Improper Neutralization of Special Elements used in an OS Command
High
CVE-2026-35463
was published
for
pyload-ng
(pip)
Apr 4, 2026
pyLoad: SSRF filter bypass via HTTP redirect in BaseDownloader (Incomplete fix for CVE-2026-33992)
Critical
CVE-2026-35459
was published
for
pyload-ng
(pip)
Apr 4, 2026
ProTip!
Advisories are also available from the
GraphQL API