GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,536
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
6,956 advisories
Filter by severity
Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks
Moderate
CVE-2026-11986
was published
for
org.keycloak:keycloak-rest-admin-ui-ext
(Maven)
Jun 11, 2026
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
High
CVE-2024-45747
was published
for
org.geoserver.web:gs-web-app
(Maven)
Aug 19, 2026
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing
High
CVE-2026-53966
was published
for
org.xwiki.platform:xwiki-platform-livedata-livetable
(Maven)
Aug 19, 2026
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
High
CVE-2026-44503
was published
for
Microsoft.Kiota.Abstractions
(Go)
May 7, 2026
Duplicate Advisory: Wildfly HAL Console Cross-Site Scripting
Moderate
GHSA-5wjw-h8x5-v65m
was published
for
org.jboss.hal:hal-console
(Maven)
Jan 14, 2025
•
withdrawn
Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition
Moderate
CVE-2026-9796
was published
for
org.keycloak:keycloak-server
(Maven)
May 28, 2026
Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML
Moderate
CVE-2026-40986
was published
for
org.springframework.webflow:spring-webflow
(Maven)
Jun 11, 2026
Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification
Moderate
CVE-2026-40992
was published
for
org.springframework.boot:spring-boot-starter-mail
(Maven)
Jun 11, 2026
Spring Web Flow has Data Binding Vulnerability with Unified EL Parser
Moderate
CVE-2026-40985
was published
for
org.springframework.webflow:spring-webflow
(Maven)
Jun 11, 2026
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
Low
CVE-2026-61634
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
Moderate
CVE-2026-63336
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
RabbitMQ Java client malformed body frame triggers raw command assembler exception
Moderate
CVE-2026-63335
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
High
CVE-2026-63337
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation
High
CVE-2026-69219
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
High
CVE-2026-69220
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
High
CVE-2026-55839
was published
for
io.kestra:kestra
(Maven)
Aug 18, 2026
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
High
CVE-2026-53659
was published
for
org.http4k:http4k-core
(Maven)
Aug 17, 2026
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
Moderate
CVE-2026-54147
was published
for
org.http4k:http4k-security-digest
(Maven)
Aug 17, 2026
http4k: `DigestAuthProvider.verify` did not bind to request URI
High
CVE-2026-54148
was published
for
org.http4k:http4k-security-digest
(Maven)
Aug 17, 2026
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
High
CVE-2026-53752
was published
for
org.docx4j:docx4j-core
(Maven)
Aug 17, 2026
Silverpeas mishandles the "Personal space" feature that is selected when no componentId is set
Moderate
CVE-2026-53698
was published
for
org.silverpeas.core:silverpeas-core
(Maven)
Jun 10, 2026
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
Moderate
CVE-2026-59903
was published
for
io.netty:netty-codec-http
(Maven)
Aug 17, 2026
Netty: Memory Exhaustion in SctpMessageCompletionHandler
High
CVE-2026-59902
was published
for
io.netty:netty-transport-sctp
(Maven)
Aug 17, 2026
carbon-apimgt does not properly restrict uploaded files
Critical
CVE-2025-13590
was published
for
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1
(Maven)
Feb 19, 2026
Jenkins GitHub Plugin has an XSS vulnerability
Critical
CVE-2026-42523
was published
for
com.coravy.hudson.plugins.github:github
(Maven)
Apr 29, 2026
ProTip!
Advisories are also available from the
GraphQL API