GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,722
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,568
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
35,444 advisories
Filter by severity
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
Moderate
CVE-2026-88000
was published
for
open-webui
(pip)
Sep 9, 2026
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Moderate
CVE-2026-88001
was published
for
open-webui
(pip)
Sep 9, 2026
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
Moderate
CVE-2026-88002
was published
for
open-webui
(pip)
Sep 9, 2026
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
High
CVE-2026-59185
was published
for
github.com/identrail/identrail
(Go)
Sep 9, 2026
@openhop/server: Path Traversal in Flow ID File Operations
High
CVE-2026-59179
was published
for
@openhop/server
(npm)
Sep 9, 2026
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
High
CVE-2026-59177
was published
for
esphome-device-builder
(pip)
Sep 9, 2026
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
High
CVE-2026-59176
was published
for
functype-mcp-server
(npm)
Sep 9, 2026
Joker linter executed project-local .jokerd/linter.* files during linting
High
CVE-2026-59172
was published
for
github.com/candid82/joker
(Go)
Sep 9, 2026
Komari: Management Interface CSRF
High
GHSA-hxjg-93wc-h8p8
was published
for
github.com/komari-monitor/komari
(Go)
Sep 9, 2026
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
High
CVE-2026-59160
was published
for
@yeger/turbo-graph
(npm)
Sep 9, 2026
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
High
CVE-2026-59158
was published
for
nuxt-ollama
(npm)
Sep 9, 2026
webhookd: Unrestricted HTTP Header to Shell Variable Injection
Moderate
CVE-2026-59157
was published
for
github.com/ncarlier/webhookd
(Go)
Sep 9, 2026
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
High
CVE-2026-55864
was published
for
org.geonetwork-opensource:gn-web-app
(Maven)
Sep 9, 2026
smol-toml: Denial of Service via malformed TOML documents
High
CVE-2026-85730
was published
for
smol-toml
(npm)
Sep 9, 2026
weasyprint Has Server-Side Request Forgery (SSRF)
Moderate
CVE-2026-55073
was published
for
weasyprint
(pip)
Sep 9, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
Moderate
CVE-2026-54529
was published
for
sqladmin
(pip)
Sep 9, 2026
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
Moderate
CVE-2026-53495
was published
for
github.com/containerd/containerd
(Go)
Sep 9, 2026
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
Moderate
CVE-2026-50024
was published
for
githacker
(pip)
Sep 9, 2026
decidim-elections: Election question titles allow stored script execution
Moderate
CVE-2026-44282
was published
for
decidim-elections
(RubyGems)
Sep 9, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
Moderate
CVE-2025-58363
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Sep 9, 2026
LF Edge eKuiper: SSRF in External Service
Moderate
CVE-2025-24979
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Sep 9, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
Low
CVE-2025-24978
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Sep 9, 2026
gix-sec safe.directory protections absent for elevated administrators
Moderate
CVE-2025-24890
was published
for
gix-sec
(Rust)
Sep 9, 2026
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
Moderate
CVE-2026-69304
was published
for
Microsoft.AspNetCore.Server.IISIntegration
(NuGet)
Sep 9, 2026
Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2026-69522
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 9, 2026
ProTip!
Advisories are also available from the
GraphQL API