GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,894
Maven
5,000+
npm
5,000+
NuGet
963
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,373
Swift
54
Unreviewed advisories
All unreviewed
5,000+
2,217 advisories
Filter by severity
ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse
Low
GHSA-qv2q-c278-pch5
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 21, 2026
ImageMagick: Division by Zero in binomial kernel
Low
GHSA-vf33-6r7x-66xx
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 21, 2026
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
Low
CVE-2026-46637
was published
for
twig/cssinliner-extra
(Composer)
May 21, 2026
Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
Low
CVE-2026-46635
was published
for
twig/twig
(Composer)
May 21, 2026
twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments
Low
CVE-2026-46629
was published
for
twig/intl-extra
(Composer)
May 21, 2026
Twig: The `spaceless` filter implicitly marks its output as safe
Low
CVE-2026-46628
was published
for
twig/twig
(Composer)
May 21, 2026
NocoDB: Stale Auth Cache After API Token Deletion
Low
CVE-2026-46554
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Attachment Size Limit Bypass via Upload-by-URL
Low
CVE-2026-46553
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
Low
CVE-2026-46549
was published
for
nocodb
(npm)
May 21, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
Low
CVE-2026-46668
was published
for
github.com/authzed/spicedb
(Go)
May 21, 2026
Crawlee for Python: SSRF via sitemap-derived URLs
Low
CVE-2026-46497
was published
for
crawlee
(pip)
May 21, 2026
androidqf: APK download Path Traversal in device APK paths
Low
GHSA-763j-3p5v-jfc6
was published
for
github.com/mvt-project/androidqf
(Go)
May 21, 2026
androidqf: Zip entry Name Injection in APK bundle (Zip Slip for zip consumers)
Low
GHSA-jf2q-463c-6f52
was published
for
github.com/mvt-project/androidqf
(Go)
May 21, 2026
@tootallnate/once vulnerable to Incorrect Control Flow Scoping
Low
CVE-2026-3449
was published
for
@tootallnate/once
(npm)
Mar 3, 2026
Apache Tomcat Uncontrolled Resource Consumption vulnerability
Low
CVE-2024-54677
was published
for
org.apache.tomcat:tomcat
(Maven)
Dec 17, 2024
TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`
Low
CVE-2026-47099
was published
for
telejson
(npm)
Apr 2, 2026
OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server
Low
GHSA-pxh5-6rrc-8rjv
was published
for
github.com/opentofu/opentofu
(Go)
May 20, 2026
pm2 Regular Expression Denial of Service vulnerability
Low
CVE-2025-5891
was published
for
pm2
(npm)
Jun 9, 2025
Open redirect endpoint in Datasette
Low
CVE-2025-64481
was published
for
datasette
(pip)
Nov 6, 2025
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
Low
CVE-2026-46342
was published
for
@nuxt/nitro-server
(npm)
May 19, 2026
Turbo: Unexpected local code execution during Yarn Berry detection
Low
CVE-2026-45772
was published
for
@turbo/codemod
(npm)
May 19, 2026
GitHub CLI: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
Low
CVE-2026-45803
was published
for
github.com/cli/cli
(Go)
May 19, 2026
FacturaScripts vulnerable to Reflected Cross-Site Scripting (XSS) via Cookie Manipulation
Low
CVE-2026-27964
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
Low
CVE-2026-45316
was published
for
open-webui
(pip)
May 14, 2026
OpenClaw: Isolated cron awareness events were recorded as trusted system events
Low
CVE-2026-44999
was published
for
openclaw
(npm)
Apr 25, 2026
ProTip!
Advisories are also available from the
GraphQL API