GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
689 advisories
Filter by severity
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error...
Moderate
Unreviewed
CVE-2026-75573
was published
Aug 27, 2026
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which...
Moderate
Unreviewed
CVE-2026-21808
was published
Aug 27, 2026
A vulnerability that records guest OS processing credentials in cleartext in a support log on the...
Moderate
Unreviewed
CVE-2026-58070
was published
Aug 27, 2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76374
was published
Aug 20, 2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76375
was published
Aug 20, 2026
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
Moderate
GHSA-hjwh-xvfw-qrwj
was published
for
mcp-searxng
(npm)
Aug 19, 2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for...
Moderate
Unreviewed
CVE-2026-75485
was published
Aug 18, 2026
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
Moderate
Unreviewed
CVE-2026-75057
was published
Aug 17, 2026
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information...
Moderate
Unreviewed
CVE-2026-59911
was published
Aug 17, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors
Moderate
CVE-2026-55102
was published
for
hashi-vault-js
(npm)
Aug 13, 2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes...
Moderate
Unreviewed
CVE-2026-18097
was published
Aug 12, 2026
MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when...
Moderate
Unreviewed
CVE-2026-19502
was published
Aug 12, 2026
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in...
Moderate
Unreviewed
CVE-2026-68969
was published
Aug 12, 2026
A flaw was found in insights-client. When the application receives a non-200 response, it logs...
Moderate
Unreviewed
CVE-2026-71474
was published
Aug 11, 2026
A flaw was found in insights-client. The setDefault() function logs the value of every...
Moderate
Unreviewed
CVE-2026-71845
was published
Aug 11, 2026
Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel...
Moderate
Unreviewed
CVE-2026-20708
was published
Aug 11, 2026
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0
Users are recommended to...
Moderate
Unreviewed
CVE-2026-65945
was published
Aug 10, 2026
When an Event Publisher output adapter is configured with irrelevant properties, the affected...
Moderate
Unreviewed
CVE-2026-0637
was published
Aug 6, 2026
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local...
Moderate
Unreviewed
CVE-2026-20289
was published
Aug 5, 2026
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a...
Moderate
Unreviewed
CVE-2026-44105
was published
Jul 30, 2026
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Moderate
CVE-2026-54704
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0...
Moderate
Unreviewed
CVE-2026-1918
was published
Jul 28, 2026
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Moderate
CVE-2026-65589
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Moderate
GHSA-fmvg-vhqq-r2mj
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
Moderate
CVE-2026-59947
was published
for
composer/composer
(Composer)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API