GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
28 advisories
Filter by severity
An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the...
High
Unreviewed
CVE-2026-44091
was published
Jul 30, 2026
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`
Moderate
CVE-2026-65902
was published
for
dompurify
(npm)
Jun 15, 2026
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
Moderate
CVE-2026-49458
was published
for
dompurify
(npm)
Jun 15, 2026
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-33828
was published
Jun 9, 2026
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
High
CVE-2026-40034
was published
for
gix
(Rust)
May 5, 2026
OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel
High
GHSA-jf56-mccx-5f3f
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intended `exec-event` downgrade
High
GHSA-gfmx-pph7-g46x
was published
for
openclaw
(npm)
Apr 9, 2026
NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not...
Moderate
Unreviewed
CVE-2026-24153
was published
Mar 31, 2026
Sandbox escape due to incorrect boundary conditions in the Telemetry component. This...
High
Unreviewed
CVE-2026-4687
was published
Mar 24, 2026
Claude Code has Sandbox Escape via Persistent Configuration Injection in settings.json
High
CVE-2026-25725
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 147...
Moderate
Unreviewed
CVE-2026-0886
was published
Jan 13, 2026
Universal Tool Calling Protocol (UTCP) client library for Python vulnerable to Trust Boundary Violation through Manual JSON specification
High
CVE-2025-14542
was published
for
utcp
(pip)
Dec 13, 2025
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
High
CVE-2025-64496
was published
for
open-webui
(npm)
Nov 7, 2025
Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server
Moderate
CVE-2025-48938
was published
for
github.com/cli/go-gh/v2
(Go)
May 30, 2025
A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode,...
Moderate
Unreviewed
CVE-2025-1118
was published
Feb 19, 2025
Open Cluster Management vulnerable to Trust Boundary Violation
High
CVE-2024-9779
was published
for
open-cluster-management.io/ocm
(Go)
Dec 18, 2024
Visual Studio Code Python Extension Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-49050
was published
Nov 12, 2024
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an...
Moderate
Unreviewed
CVE-2024-20265
was published
Mar 27, 2024
kubevirt-csi: PersistentVolume allows access to HCP's root node
High
CVE-2024-1725
was published
for
github.com/kubevirt/csi-driver
(Go)
Mar 7, 2024
Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox
High
GHSA-hj55-9jmv-9jrj
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Jan 19, 2024
•
withdrawn
Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which...
High
Unreviewed
CVE-2023-0627
was published
Sep 25, 2023
Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If...
High
Unreviewed
CVE-2023-28597
was published
Jul 6, 2023
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are...
Moderate
Unreviewed
CVE-2022-20826
was published
Nov 16, 2022
Class Loading Vulnerability in Artemis
High
CVE-2024-23682
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Feb 9, 2022
ProTip!
Advisories are also available from the
GraphQL API