GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
344 advisories
Filter by severity
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
Moderate
CVE-2026-73304
was published
for
@budibase/server
(npm)
Jul 24, 2026
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
Moderate
CVE-2026-70599
was published
for
electron
(npm)
Aug 5, 2026
Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
Moderate
GHSA-8gj2-2cvc-6xx7
was published
for
flowise
(npm)
Aug 4, 2026
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
Moderate
CVE-2026-67439
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
High
GHSA-qw6m-8fw2-2v64
was published
for
@budibase/server
(npm)
Jul 24, 2026
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
High
CVE-2026-55575
was published
for
liquidjs
(npm)
Jul 24, 2026
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
High
CVE-2026-45623
was published
for
postcss
(npm)
Jul 23, 2026
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`
Moderate
CVE-2026-65902
was published
for
dompurify
(npm)
Jun 15, 2026
DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output
Low
CVE-2026-65899
was published
for
dompurify
(npm)
Jun 15, 2026
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
High
CVE-2026-54351
was published
for
@budibase/server
(npm)
Jun 22, 2026
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
High
CVE-2026-40938
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
Moderate
CVE-2026-59929
was published
for
mistune
(pip)
Jul 20, 2026
Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
Moderate
CVE-2026-59930
was published
for
mistune
(pip)
Jul 20, 2026
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
High
CVE-2026-59925
was published
for
mistune
(pip)
Jul 20, 2026
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
High
CVE-2026-59928
was published
for
mistune
(pip)
Jul 20, 2026
Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows
Moderate
CVE-2026-56268
was published
for
flowise
(npm)
May 20, 2026
FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`
Critical
CVE-2026-45262
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass
Moderate
CVE-2026-52820
was published
for
kimai/kimai
(Composer)
Jul 13, 2026
Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target
Moderate
CVE-2026-52819
was published
for
kimai/kimai
(Composer)
Jul 13, 2026
Micronaut has unbounded `formattersCache` in `TimeConverterRegistrar` that Allows Memory Exhaustion via `Accept-Language` Header
High
CVE-2026-44241
was published
for
io.micronaut:micronaut-context
(Maven)
May 6, 2026
LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
High
CVE-2026-45617
was published
for
liquidjs
(npm)
May 27, 2026
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
High
CVE-2026-45357
was published
for
liquidjs
(npm)
May 27, 2026
LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`
Moderate
CVE-2026-44646
was published
for
liquidjs
(npm)
May 27, 2026
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
Moderate
CVE-2026-44645
was published
for
liquidjs
(npm)
May 27, 2026
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
Moderate
CVE-2026-44644
was published
for
liquidjs
(npm)
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API