GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,128 advisories
Filter by severity
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
Low
CVE-2026-55785
was published
for
github.com/free5gc/ausf
(Go)
Aug 28, 2026
Potential for logging sensitive data in Spring Cloud Function AWS.
Spring Cloud Function 5.0.0 -...
Low
Unreviewed
CVE-2026-59300
was published
Aug 27, 2026
Potential for logging sensitive data in Spring Cloud Stream.
Spring Cloud Stream 5.0.0 - 5.0.2...
Low
Unreviewed
CVE-2026-59302
was published
Aug 27, 2026
Potential for logging sensitive data in Spring Cloud Function Azure.
Spring Cloud Function 5.0.0 ...
Low
Unreviewed
CVE-2026-59301
was published
Aug 27, 2026
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver...
High
Unreviewed
CVE-2026-81715
was published
Aug 27, 2026
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the...
High
Unreviewed
CVE-2026-81705
was published
Aug 27, 2026
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error...
Moderate
Unreviewed
CVE-2026-75573
was published
Aug 27, 2026
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which...
Moderate
Unreviewed
CVE-2026-21808
was published
Aug 27, 2026
A vulnerability that records guest OS processing credentials in cleartext in a support log on the...
Moderate
Unreviewed
CVE-2026-58070
was published
Aug 27, 2026
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
High
CVE-2026-61798
was published
for
io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl
(Maven)
Aug 20, 2026
A low privileged remote attacker can hijack an active administrative session without needing to...
High
Unreviewed
CVE-2026-14948
was published
Aug 20, 2026
In affected versions of Octopus Server under certain circumstances it is possible for sensitive...
High
Unreviewed
CVE-2026-14163
was published
Aug 20, 2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76374
was published
Aug 20, 2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76375
was published
Aug 20, 2026
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
Moderate
GHSA-hjwh-xvfw-qrwj
was published
for
mcp-searxng
(npm)
Aug 19, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's...
High
Unreviewed
CVE-2020-37267
was published
Aug 19, 2026
Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request...
High
Unreviewed
CVE-2019-25766
was published
Aug 19, 2026
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role,...
Critical
Unreviewed
CVE-2026-66780
was published
Aug 18, 2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for...
Moderate
Unreviewed
CVE-2026-75485
was published
Aug 18, 2026
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
Moderate
Unreviewed
CVE-2026-75057
was published
Aug 17, 2026
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information...
Moderate
Unreviewed
CVE-2026-59911
was published
Aug 17, 2026
openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the ...
High
Unreviewed
CVE-2026-74870
was published
Aug 17, 2026
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed...
High
Unreviewed
CVE-2026-19483
was published
Aug 13, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors
Moderate
CVE-2026-55102
was published
for
hashi-vault-js
(npm)
Aug 13, 2026
ProTip!
Advisories are also available from the
GraphQL API