GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
63 advisories
Filter by severity
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
High
CVE-2026-61798
was published
for
io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl
(Maven)
Aug 20, 2026
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
Moderate
CVE-2026-54704
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
Moderate
CVE-2026-45581
was published
for
org.hyperledger.fabric-chaincode-java:fabric-chaincode-shim
(Maven)
May 19, 2026
Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer
High
CVE-2026-44516
was published
for
com.ritense.valtimo:web
(Maven)
May 11, 2026
Spring Cloud Config Server Logged Sensitive Information
Moderate
CVE-2026-41004
was published
for
org.springframework.cloud:spring-cloud-config-server
(Maven)
May 7, 2026
Apache Kafka exposes sensitive information in its DEBUG logs
Moderate
CVE-2026-33558
was published
for
org.apache.kafka:kafka-clients
(Maven)
Apr 20, 2026
Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService
Moderate
CVE-2026-34164
was published
for
com.ritense.valtimo:inbox
(Maven)
Apr 16, 2026
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
High
CVE-2026-34487
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
Apache Cassandra has sensitive Information Leak in cqlsh
Moderate
CVE-2026-27315
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Apr 7, 2026
Apache ZooKeeper has improper handling of configuration values
High
CVE-2026-24308
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Mar 7, 2026
Neo4j Enterprise and Community vulnerable to a potential information disclosure
Moderate
CVE-2026-1622
was published
for
org.neo4j:neo4j
(Maven)
Feb 4, 2026
Apache Linkis: Password Exposure
Moderate
CVE-2025-59355
was published
for
org.apache.linkis:linkis-metadata
(Maven)
Jan 19, 2026
Liferay Portal Vulnerable to Information Exposure Through a Log File Vulnerability in LDAP Import Feature
Moderate
CVE-2025-62262
was published
for
com.liferay:com.liferay.portal.security.ldap.impl
(Maven)
Oct 27, 2025
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Moderate
CVE-2025-37727
was published
for
org.elasticsearch:elasticsearch
(Maven)
Oct 10, 2025
sentry-android unmasked sensitive data in Android Session Replays for users of Jetpack Compose 1.8+
High
GHSA-7cjh-xx4r-qh3f
was published
for
io.sentry:sentry-android
(Maven)
Jun 20, 2025
Para Inserts Sensitive Information into Log File for Facebook authentication
Moderate
CVE-2025-49009
was published
for
com.erudika:para-server
(Maven)
Jun 6, 2025
Para Server Logs Sensitive Information
Moderate
CVE-2025-48955
was published
for
com.erudika:para-server
(Maven)
May 30, 2025
Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
Moderate
CVE-2025-26795
was published
for
org.apache.iotdb:iotdb-jdbc
(Maven)
May 14, 2025
Apache ActiveMQ Artemis Vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-27391
was published
for
org.apache.activemq:artemis-project
(Maven)
Apr 9, 2025
Apache Pulsar Kafka Connector Logs Sensitive Information in Application Logs
Moderate
CVE-2025-30677
was published
for
org.apache.pulsar:pulsar-io-kafka
(Maven)
Apr 9, 2025
Snowflake JDBC Driver client-side encryption key in DEBUG logs
Low
CVE-2025-27496
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Mar 13, 2025
Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
Moderate
CVE-2024-52067
was published
for
org.apache.nifi:nifi-framework-core
(Maven)
Feb 11, 2025
Infinispan vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-0736
was published
for
org.infinispan:infinispan-parent
(Maven)
Jan 28, 2025
Quarkus CXF logs passwords and other secrets
Moderate
CVE-2024-9621
was published
for
io.quarkiverse.cxf:quarkus-cxf
(Maven)
Oct 8, 2024
Elasticsearch Insertion of Sensitive Information into Log File
Moderate
CVE-2023-49921
was published
for
org.elasticsearch:elasticsearch
(Maven)
Jul 26, 2024
ProTip!
Advisories are also available from the
GraphQL API