GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
549 advisories
Filter by severity
Blocky DNSSEC validation bypass and validation-cache scope pollution
High
GHSA-x845-2f78-7v36
was published
for
github.com/0xERR0R/blocky
(Go)
Jun 19, 2026
Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)
High
GHSA-v52w-28xh-v562
was published
for
@kozou/api
(npm)
Jun 19, 2026
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
Moderate
CVE-2026-55767
was published
for
guzzlehttp/guzzle
(Composer)
Jun 19, 2026
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
High
CVE-2026-6734
was published
for
undici
(npm)
Jun 19, 2026
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
High
CVE-2026-57112
was published
for
praisonai
(pip)
Jun 18, 2026
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
Moderate
CVE-2026-55669
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
Moderate
CVE-2026-9595
was published
for
webpack-dev-server
(npm)
Jun 17, 2026
Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
High
CVE-2026-54007
was published
for
open-webui
(pip)
Jun 17, 2026
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-12304
was published
Jun 16, 2026
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted...
High
Unreviewed
CVE-2026-47825
was published
Jun 15, 2026
@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass
High
CVE-2026-50168
was published
for
@angular/platform-server
(npm)
Jun 15, 2026
The Model Context Protocol has a security warning advising servers to validate the "Origin"...
Critical
Unreviewed
CVE-2026-11624
was published
Jun 13, 2026
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
High
GHSA-j9gf-vw2f-9hrw
was published
for
com.appsmith:server
(Maven)
Jun 12, 2026
Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1...
High
Unreviewed
CVE-2026-45173
was published
Jun 12, 2026
Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115...
Low
Unreviewed
CVE-2026-12032
was published
Jun 12, 2026
Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a...
Moderate
Unreviewed
CVE-2026-12024
was published
Jun 12, 2026
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
Moderate
CVE-2026-48022
was published
for
@hapi/wreck
(npm)
Jun 11, 2026
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross...
High
Unreviewed
CVE-2026-41700
was published
Jun 11, 2026
Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload
Critical
CVE-2026-48063
was published
for
@whiskeysockets/baileys
(npm)
Jun 10, 2026
NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub)...
High
Unreviewed
CVE-2026-10846
was published
Jun 10, 2026
SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending...
Moderate
Unreviewed
CVE-2026-44755
was published
Jun 9, 2026
Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote...
High
Unreviewed
CVE-2026-11693
was published
Jun 9, 2026
Netty has Insufficient Bailiwick Validation for NS Records
High
CVE-2026-47691
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
High
CVE-2026-45674
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
Origin Validation Error vulnerability in ninenines gun (gun_http2 module) allows cross-origin...
Moderate
Unreviewed
CVE-2026-43972
was published
Jun 8, 2026
ProTip!
Advisories are also available from the
GraphQL API