GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,538
Maven
5,000+
npm
5,000+
NuGet
914
pip
4,790
Pub
13
RubyGems
1,037
Rust
1,232
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,354 advisories
Filter by severity
Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass)
Moderate
GHSA-f3g8-9xv5-77gv
was published
for
@saltcorn/server
(npm)
Apr 16, 2026
Grafana Loki Path Traversal - CVE-2021-36156 Bypass
Moderate
CVE-2026-21726
was published
for
github.com/grafana/loki/v3
(Go)
Apr 15, 2026
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an...
Moderate
Unreviewed
CVE-2026-20060
was published
Apr 15, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint
Low
GHSA-7qx6-f23w-3w7f
was published
for
github.com/patrickhener/goshs
(Go)
Apr 14, 2026
@adonisjs/http-server has an Open Redirect vulnerability
Moderate
CVE-2026-40255
was published
for
@adonisjs/core
(npm)
Apr 14, 2026
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in...
Low
Unreviewed
CVE-2026-21741
was published
Apr 14, 2026
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an...
Moderate
Unreviewed
CVE-2026-34257
was published
Apr 14, 2026
Kimai has an Open Redirect via Unvalidated RelayState in SAML ACS Handler
Low
GHSA-3jp4-mhh4-gcgr
was published
for
kimai/kimai
(Composer)
Apr 14, 2026
The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in...
Moderate
Unreviewed
CVE-2026-6203
was published
Apr 14, 2026
next-intl has an open redirect vulnerability
Moderate
CVE-2026-40299
was published
for
next-intl
(npm)
Apr 10, 2026
An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be...
Moderate
Unreviewed
CVE-2026-22560
was published
Apr 10, 2026
Apache Tomcat has an Open Redirect vulnerability
Moderate
CVE-2026-25854
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects
High
GHSA-pg8g-f2hf-x82m
was published
for
openclaw
(npm)
Apr 9, 2026
•
withdrawn
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost...
Moderate
Unreviewed
CVE-2026-39484
was published
Apr 8, 2026
A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking...
High
Unreviewed
CVE-2026-23818
was published
Apr 7, 2026
An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a...
Moderate
Unreviewed
CVE-2025-61166
was published
Apr 6, 2026
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri
High
GHSA-x3f4-v83f-7wp2
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
Microsoft 7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash...
High
Unreviewed
CVE-2018-25245
was published
Apr 4, 2026
Directus: Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow
Moderate
CVE-2026-35410
was published
for
directus
(npm)
Apr 4, 2026
Directus: Open Redirect in Admin 2FA Setup Page
Moderate
CVE-2026-35411
was published
for
directus
(npm)
Apr 4, 2026
Signal K Server: OAuth Authorization Code Theft via Unvalidated Host Header in OIDC Flow
Moderate
CVE-2026-34083
was published
for
signalk-server
(npm)
Apr 3, 2026
JupyterHub has an Open Redirect Vulnerability
Moderate
CVE-2026-33709
was published
for
jupyterhub
(pip)
Apr 3, 2026
Casdoor vulnerable to Open Redirect
Low
CVE-2026-5467
was published
for
github.com/casdoor/casdoor
(Go)
Apr 3, 2026
Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint
High
CVE-2026-3872
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 2, 2026
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container...
Low
Unreviewed
CVE-2026-2475
was published
Apr 1, 2026
ProTip!
Advisories are also available from the
GraphQL API