GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,578
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
34,792 advisories
Filter by severity
OpenSTAManager has HTML Injection in modules/utenti/edit.php
Low
CVE-2026-44701
was published
for
devcode-it/openstamanager
(Composer)
Aug 26, 2026
LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
High
GHSA-7w8c-qgxg-m7jx
was published
for
librenms/librenms
(Composer)
Aug 26, 2026
asyncssh has SCP Path Traversal to Arbitrary File Write
High
CVE-2026-54591
was published
for
asyncssh
(pip)
Aug 26, 2026
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
Moderate
CVE-2026-54590
was published
for
asyncssh
(pip)
Aug 26, 2026
cakephp/debug_kit: MailPreview contains unsafe reflection
Moderate
CVE-2026-54614
was published
for
cakephp/debug_kit
(Composer)
Aug 26, 2026
senaite.core Vulnerable to Eval Injection and Missing Authorization
Critical
CVE-2026-54569
was published
for
senaite.core
(pip)
Aug 26, 2026
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed
High
CVE-2026-54606
was published
for
suneditor
(npm)
Aug 26, 2026
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
High
CVE-2026-54563
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Aug 26, 2026
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
Moderate
GHSA-x287-5c68-36wp
was published
for
openwisp-ipam
(pip)
Aug 26, 2026
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
Critical
GHSA-93qj-5q5v-3c2h
was published
for
pantheon-agents
(pip)
Aug 26, 2026
AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
Moderate
CVE-2026-55688
was published
for
org.asynchttpclient:async-http-client
(Maven)
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
CVE-2026-54786
was published
for
wasmtime-wasi
(Rust)
Aug 26, 2026
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
High
CVE-2026-54511
was published
for
@logtape/syslog
(npm)
Aug 26, 2026
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
High
CVE-2026-54550
was published
for
org.codehaus.izpack:izpack-installer
(Maven)
Aug 26, 2026
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
Critical
CVE-2026-54523
was published
for
github.com/kyverno/kyverno
(Go)
Aug 26, 2026
kas Persistently Disables SSH Host Key Checking
Low
CVE-2026-54548
was published
for
kas
(pip)
Aug 26, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Moderate
CVE-2026-54553
was published
for
starlette-admin
(pip)
Aug 26, 2026
http4s has HTTP/2 Denial of Service with Ember Backend
High
CVE-2026-54556
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Aug 26, 2026
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`
High
CVE-2026-54356
was published
for
@budibase/server
(npm)
Aug 26, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
Moderate
CVE-2026-54338
was published
for
jupyterhub
(pip)
Aug 25, 2026
icalendar has Algorithmic Complexity in Equality
High
CVE-2026-55099
was published
for
icalendar
(pip)
Aug 25, 2026
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
High
CVE-2026-45019
was published
for
chainlit
(pip)
Aug 25, 2026
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
Critical
CVE-2026-45018
was published
for
chainlit
(pip)
Aug 25, 2026
@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
Moderate
CVE-2026-55605
was published
for
@arikusi/deepseek-mcp-server
(npm)
Aug 25, 2026
@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
High
CVE-2026-55604
was published
for
@arikusi/deepseek-mcp-server
(npm)
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API