GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
189 advisories
Filter by severity
RestrictedPython guard hooks can be shadowed via positional-only arguments
High
CVE-2026-55830
was published
for
RestrictedPython
(pip)
Aug 28, 2026
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an...
Critical
Unreviewed
CVE-2026-65083
was published
Aug 25, 2026
The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands...
High
Unreviewed
CVE-2026-76072
was published
Aug 24, 2026
The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against...
Low
Unreviewed
CVE-2026-18356
was published
Aug 21, 2026
The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues...
Moderate
Unreviewed
CVE-2026-72860
was published
Aug 21, 2026
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the...
Critical
Unreviewed
CVE-2026-74886
was published
Aug 17, 2026
Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails...
High
Unreviewed
CVE-2026-73484
was published
Aug 13, 2026
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2,...
Moderate
Unreviewed
CVE-2026-70466
was published
Aug 12, 2026
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
High
CVE-2026-52776
was published
for
compliance-trestle
(pip)
Aug 12, 2026
Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read...
High
Unreviewed
CVE-2026-72779
was published
Aug 11, 2026
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
Moderate
GHSA-957r-qf9p-67xw
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due...
High
Unreviewed
CVE-2026-17630
was published
Aug 5, 2026
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
High
Unreviewed
CVE-2026-71259
was published
Aug 5, 2026
Ghost: Private IP filtering bypass to make server-side requests to internal services
Moderate
CVE-2026-53944
was published
for
ghost
(npm)
Aug 4, 2026
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
Critical
CVE-2026-70470
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
High
CVE-2026-69263
was published
for
flowise
(npm)
Aug 4, 2026
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
Moderate
CVE-2026-52888
was published
for
@nocobase/plugin-collection-sql
(npm)
Jul 28, 2026
GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
High
GHSA-6p8h-3wgx-97gf
was published
for
GitPython
(pip)
Jul 24, 2026
In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is...
Moderate
Unreviewed
CVE-2026-50251
was published
Jul 22, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Low
GHSA-5qhf-9phg-95m2
was published
for
loofah
(RubyGems)
Jul 21, 2026
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
High
GHSA-2f96-g7mh-g2hx
was published
for
GitPython
(pip)
Jul 21, 2026
SVGO removeScripts plugin leaves some executable scripts intact
High
CVE-2026-73650
was published
for
svgo
(npm)
Jul 21, 2026
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
Low
GHSA-c2j3-45gr-mqc4
was published
for
dompurify
(npm)
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Low
CVE-2026-73491
was published
for
loofah
(RubyGems)
Jul 21, 2026
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
Moderate
CVE-2026-59929
was published
for
mistune
(pip)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API