GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,128 advisories
Filter by severity
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes...
Moderate
Unreviewed
CVE-2026-18097
was published
Aug 12, 2026
MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when...
Moderate
Unreviewed
CVE-2026-19502
was published
Aug 12, 2026
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in...
Moderate
Unreviewed
CVE-2026-68969
was published
Aug 12, 2026
A flaw was found in insights-client. The setDefault() function logs the value of every...
Moderate
Unreviewed
CVE-2026-71845
was published
Aug 11, 2026
A flaw was found in insights-client. When the application receives a non-200 response, it logs...
Moderate
Unreviewed
CVE-2026-71474
was published
Aug 11, 2026
Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel...
Moderate
Unreviewed
CVE-2026-20708
was published
Aug 11, 2026
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0
Users are recommended to...
Moderate
Unreviewed
CVE-2026-65945
was published
Aug 10, 2026
When an Event Publisher output adapter is configured with irrelevant properties, the affected...
Moderate
Unreviewed
CVE-2026-0637
was published
Aug 6, 2026
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local...
Moderate
Unreviewed
CVE-2026-20289
was published
Aug 5, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores...
High
Unreviewed
CVE-2026-12947
was published
Jul 30, 2026
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a...
Moderate
Unreviewed
CVE-2026-44105
was published
Jul 30, 2026
The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy...
Low
Unreviewed
CVE-2026-59326
was published
Jul 30, 2026
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Moderate
CVE-2026-54704
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain...
High
Unreviewed
CVE-2026-14528
was published
Jul 28, 2026
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0...
Moderate
Unreviewed
CVE-2026-1918
was published
Jul 28, 2026
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
Low
GHSA-2625-rw7m-5q5x
was published
for
hubuum_client
(Rust)
Jul 24, 2026
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
Low
Unreviewed
CVE-2026-64800
was published
Jul 23, 2026
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Moderate
CVE-2026-65589
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Moderate
GHSA-fmvg-vhqq-r2mj
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
Moderate
CVE-2026-59947
was published
for
composer/composer
(Composer)
Jul 20, 2026
OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the...
Moderate
Unreviewed
CVE-2026-62211
was published
Jul 17, 2026
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2...
High
Unreviewed
CVE-2026-40633
was published
Jul 15, 2026
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker...
Moderate
Unreviewed
CVE-2026-50316
was published
Jul 14, 2026
Various sensitive information such as passwords and charging card UIDs are written to log files.
Critical
Unreviewed
CVE-2026-22098
was published
Jul 13, 2026
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The...
Moderate
Unreviewed
CVE-2026-56459
was published
Jul 9, 2026
ProTip!
Advisories are also available from the
GraphQL API