GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,894
Maven
5,000+
npm
5,000+
NuGet
963
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,373
Swift
54
Unreviewed advisories
All unreviewed
5,000+
1,387 advisories
Filter by severity
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
Moderate
CVE-2026-46616
was published
for
Umbraco.Cms
(NuGet)
May 21, 2026
ArcGIS Server contains an input validation weakness in the login redirection workflow. An...
Moderate
Unreviewed
CVE-2026-2813
was published
May 20, 2026
A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a...
High
Unreviewed
CVE-2026-7504
was published
May 19, 2026
SimpleSAMLphp casserver: Open Redirect in logout
Moderate
CVE-2025-65954
was published
for
simplesamlphp/simplesamlphp-module-casserver
(Composer)
May 15, 2026
CWE-601 URL redirection to untrusted site ('open redirect')
Moderate
Unreviewed
CVE-2026-45448
was published
May 14, 2026
Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect
Moderate
CVE-2026-44681
was published
for
authlib
(pip)
May 13, 2026
Snipe-IT has an open redirect vulnerability
Moderate
CVE-2026-44833
was published
for
snipe/snipe-it
(Composer)
May 8, 2026
Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click
High
CVE-2026-43941
was published
for
electerm
(npm)
May 8, 2026
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware
Moderate
CVE-2026-44427
was published
for
github.com/modelcontextprotocol/registry
(Go)
May 8, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
Moderate
CVE-2026-40295
was published
for
devise
(RubyGems)
May 8, 2026
Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The...
Moderate
Unreviewed
CVE-2026-3318
was published
May 8, 2026
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
High
GHSA-p64j-f4x9-wq66
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information...
Critical
Unreviewed
CVE-2026-6795
was published
May 7, 2026
docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler
Moderate
CVE-2026-44520
was published
for
docling-graph
(pip)
May 7, 2026
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
High
CVE-2026-44503
was published
for
Microsoft.Kiota.Abstractions
(Go)
May 7, 2026
Angular SSR has Open Redirect and Request Steering via Encoded X-Forwarded-Prefix
Moderate
CVE-2026-44437
was published
for
@angular/ssr
(npm)
May 6, 2026
Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules
Moderate
CVE-2026-44372
was published
for
nitro
(npm)
May 6, 2026
Duplicate Advisory: OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets
Moderate
GHSA-3r56-7hhr-vfg9
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
wger: trainer_login open redirect - ?next= parameter not validated against host
Moderate
GHSA-vqv8-j3mj-wjxj
was published
for
wger
(pip)
May 6, 2026
Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported...
Moderate
Unreviewed
CVE-2026-35253
was published
May 6, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
Moderate
CVE-2026-42207
was published
for
openmage/magento-lts
(Composer)
May 5, 2026
@workos/authkit-session has an Open Redirect via state-derived redirect target
Moderate
CVE-2026-42565
was published
for
@workos/authkit-session
(npm)
May 5, 2026
Jupyter Server has an open redirection vulnerability in `next` query parameter
Moderate
CVE-2025-61669
was published
for
jupyter-server
(pip)
May 5, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
High
CVE-2026-40171
was published
for
@jupyter-notebook/help-extension
(npm)
Apr 30, 2026
Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web...
Moderate
Unreviewed
CVE-2026-41226
was published
Apr 30, 2026
ProTip!
Advisories are also available from the
GraphQL API