GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
542 advisories
Filter by severity
Inappropriate implementation in Extensions in Google Chrome on Android prior to 150.0.7871.47...
Moderate
Unreviewed
CVE-2026-13822
was published
Jul 1, 2026
Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47...
Moderate
Unreviewed
CVE-2026-13826
was published
Jul 1, 2026
Insufficient policy enforcement in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote...
Moderate
Unreviewed
CVE-2026-13793
was published
Jul 1, 2026
Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that...
High
Unreviewed
CVE-2026-58169
was published
Jun 30, 2026
A cross-origin issue was addressed with improved tracking of security origins. This issue is...
Moderate
Unreviewed
CVE-2026-43700
was published
Jun 29, 2026
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
High
CVE-2026-55487
was published
for
pnpm
(npm)
Jun 26, 2026
chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution
High
GHSA-9g5q-2w5x-hmxf
was published
for
github.com/go-chi/chi/middleware
(Go)
Jun 25, 2026
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a...
Moderate
Unreviewed
CVE-2026-13034
was published
Jun 24, 2026
Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0...
Moderate
Unreviewed
CVE-2026-13021
was published
Jun 24, 2026
Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a...
Moderate
Unreviewed
CVE-2026-13022
was published
Jun 24, 2026
Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
Moderate
CVE-2026-46611
was published
for
glances
(pip)
Jun 22, 2026
Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request...
Moderate
Unreviewed
CVE-2026-54665
was published
Jun 22, 2026
Anki's local HTTP server does not sufficiently validate requests
High
CVE-2026-59153
was published
for
aqt
(pip)
Jun 19, 2026
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
High
GHSA-f4xh-w4cj-qxq8
was published
for
langsmith
(pip)
Jun 19, 2026
Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests
High
GHSA-v3f4-w7r7-v3hm
was published
for
@zenalexa/unicli
(npm)
Jun 19, 2026
dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
Moderate
CVE-2026-55837
was published
for
dbt-mcp
(pip)
Jun 19, 2026
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
High
CVE-2026-55660
was published
for
@tinacms/app
(npm)
Jun 19, 2026
Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
Critical
CVE-2026-55791
was published
for
craftcms/cms
(Composer)
Jun 19, 2026
Blocky DNSSEC validation bypass and validation-cache scope pollution
High
GHSA-x845-2f78-7v36
was published
for
github.com/0xERR0R/blocky
(Go)
Jun 19, 2026
Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)
High
GHSA-v52w-28xh-v562
was published
for
@kozou/api
(npm)
Jun 19, 2026
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
Moderate
CVE-2026-55767
was published
for
guzzlehttp/guzzle
(Composer)
Jun 19, 2026
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
High
CVE-2026-6734
was published
for
undici
(npm)
Jun 19, 2026
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
High
CVE-2026-57112
was published
for
praisonai
(pip)
Jun 18, 2026
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
Moderate
CVE-2026-55669
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
Moderate
CVE-2026-9595
was published
for
webpack-dev-server
(npm)
Jun 17, 2026
ProTip!
Advisories are also available from the
GraphQL API