GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,578
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
320 advisories
Filter by severity
A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI...
Critical
Unreviewed
CVE-2026-19485
was published
Aug 26, 2026
Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked...
Moderate
Unreviewed
CVE-2026-56706
was published
Aug 25, 2026
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
Moderate
GHSA-92hr-gmr6-h8cp
was published
for
ep_etherpad-lite
(npm)
Aug 17, 2026
A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the...
Moderate
Unreviewed
CVE-2026-19906
was published
Aug 15, 2026
A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C,...
Low
Unreviewed
CVE-2026-19748
was published
Aug 13, 2026
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with...
Moderate
Unreviewed
CVE-2026-18531
was published
Aug 5, 2026
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large...
Moderate
Unreviewed
CVE-2026-71225
was published
Aug 5, 2026
Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket....
Moderate
Unreviewed
CVE-2026-66391
was published
Jul 27, 2026
Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection
Low
GHSA-gq4g-fpc9-vjfq
was published
for
web-auth/webauthn-lib
(Composer)
Jul 7, 2026
Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased...
High
Unreviewed
CVE-2026-14570
was published
Jul 5, 2026
RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins
Moderate
CVE-2022-31008
was published
for
rabbit_common
(Erlang)
Jun 30, 2026
Net::BitTorrent versions through 2.0.1 for Perl generate the MSE Diffie-Hellman private key with...
Moderate
Unreviewed
CVE-2026-57082
was published
Jun 30, 2026
Netty: QUIC stateless reset token material exposed through header-visible connection IDs
Moderate
CVE-2026-50009
was published
for
io.netty:netty-codec-classes-quic
(Maven)
Jun 15, 2026
Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue
Moderate
CVE-2026-41701
was published
for
org.springframework.amqp:spring-amqp
(Maven)
Jun 10, 2026
Spring Framework Predictable Session ID in WebSocket Module
Moderate
CVE-2026-41838
was published
for
org.springframework:spring-websocket
(Maven)
Jun 9, 2026
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
Moderate
CVE-2026-45673
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
Moderate
CVE-2026-47703
was published
for
github.com/AdguardTeam/AdGuardHome
(Go)
Jun 4, 2026
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard...
Critical
Unreviewed
CVE-2026-50208
was published
Jun 4, 2026
netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures
Moderate
CVE-2026-41207
was published
for
io.netty.incubator:netty-incubator-codec-ohttp
(Maven)
May 26, 2026
ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse
Low
GHSA-qv2q-c278-pch5
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 21, 2026
Netatalk 2.0.0 through 4.4.2 generates AFP session tokens derived from predictable process IDs,...
Moderate
Unreviewed
CVE-2026-44054
was published
May 21, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
CVE-2026-42155
was published
for
openmage/magento-lts
(Composer)
May 5, 2026
Langchain-Chatchat Uses Insufficiently Random Values
Low
CVE-2026-7847
was published
for
langchain-chatchat
(pip)
May 5, 2026
Spring Boot's random value property source uses a weak PRNG unsuitable for secrets
Moderate
CVE-2026-40975
was published
for
org.springframework.boot:spring-boot-cassandra
(Maven)
Apr 28, 2026
DNN: Same HostGUID for all new installs
Moderate
CVE-2026-40306
was published
for
DotNetNuke.Core
(NuGet)
Apr 10, 2026
ProTip!
Advisories are also available from the
GraphQL API