GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
Moderate
GHSA-jqwr-vx3p-r266
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
High
CVE-2026-59209
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
Moderate
CVE-2026-54303
was published
for
n8n
(npm)
Jun 16, 2026
n8n: Merge Node SQL Mode Prototype Pollution
Moderate
CVE-2026-54311
was published
for
n8n
(npm)
Jun 16, 2026
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
Moderate
CVE-2026-54306
was published
for
n8n
(npm)
Jun 16, 2026
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
Moderate
CVE-2026-54313
was published
for
n8n
(npm)
Jun 16, 2026
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
Moderate
CVE-2026-54310
was published
for
n8n
(npm)
Jun 16, 2026
n8n Has a Source Control Pull SQL Injection
High
CVE-2026-44792
was published
for
n8n
(npm)
May 14, 2026
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
Critical
CVE-2026-44789
was published
for
n8n
(npm)
May 14, 2026
n8n has SQL Injection in SeaTable Node
Moderate
CVE-2026-42229
was published
for
n8n
(npm)
Apr 29, 2026
Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization
Critical
CVE-2026-39324
was published
for
rack-session
(RubyGems)
Apr 8, 2026
Traefik has unbounded io.ReadAll on auth server response body that causes OOM DOS
Moderate
CVE-2026-26998
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 4, 2026
n8n has an Authentication Bypass in its Chat Trigger Node
Moderate
GHSA-jh8h-6c9q-7gmw
was published
for
n8n
(npm)
Feb 26, 2026
ProTip!
Advisories are also available from the
GraphQL API