GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
7,013 advisories
Filter by severity
mathlive's Lack of Escaping of HTML allows for XSS
Moderate
CVE-2026-54705
was published
for
mathlive
(npm)
Jul 29, 2026
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
High
CVE-2026-11393
was published
for
@aws/agentcore
(npm)
Jul 29, 2026
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
Low
GHSA-pc2w-4mq8-32qw
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
High
CVE-2026-54666
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped enum string values
High
CVE-2026-54664
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
High
CVE-2026-54661
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
Moderate
CVE-2026-54663
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
High
CVE-2026-54662
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
High
CVE-2026-54660
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
Style Dictionary - Prototype Pollution in convertTokenData utility function
High
CVE-2026-54639
was published
for
style-dictionary
(npm)
Jul 28, 2026
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
Critical
CVE-2026-54658
was published
for
@hypequery/clickhouse
(npm)
Jul 28, 2026
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
Moderate
CVE-2026-52888
was published
for
@nocobase/plugin-collection-sql
(npm)
Jul 28, 2026
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
Moderate
GHSA-vg6v-j97m-h5xq
was published
for
@novu/application-generic
(npm)
Jul 28, 2026
@wakaru/cli arbitrary file write during bundle unpack
High
CVE-2026-54545
was published
for
@wakaru/cli
(npm)
Jul 28, 2026
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
Moderate
GHSA-8q49-2h5h-434x
was published
for
@frontmcp/adapters
(npm)
Jul 24, 2026
Quasar: Prototype pollution in the extend() utility
Moderate
GHSA-3r53-75j5-3g7j
was published
for
quasar
(npm)
Jul 24, 2026
Shescape: Quadratic-time denial of service in the flag-protection
High
GHSA-gm3r-q2wp-hw87
was published
for
shescape
(npm)
Jul 24, 2026
Shescape: Home-directory disclosure in assignment context on Unix with Dash
Moderate
GHSA-q53c-4prm-w95q
was published
for
shescape
(npm)
Jul 24, 2026
Shescape: Shell injection via unescaped parentheses on Windows with CMD
Critical
GHSA-w4hw-qcx7-56pr
was published
for
shescape
(npm)
Jul 24, 2026
Shescape: Path disclosure on Unix with Zsh
Moderate
GHSA-6v4m-fw66-8r4x
was published
for
shescape
(npm)
Jul 24, 2026
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
High
CVE-2026-14257
was published
for
brace-expansion
(npm)
Jul 24, 2026
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
Critical
GHSA-vh45-f885-3848
was published
for
sm-crypto
(npm)
Jul 24, 2026
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
High
GHSA-g5vv-q72c-7j78
was published
for
@anephenix/hub
(npm)
Jul 24, 2026
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
Moderate
GHSA-hfhx-w8p8-4hc7
was published
for
@budibase/server
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API