GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
9,078 advisories
Filter by severity
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access
High
CVE-2026-26187
was published
for
github.com/treeverse/lakefs
(Go)
Feb 13, 2026
Keycloak fails to verify if an Identity Provider (IdP) is enabled before issuing tokens
High
CVE-2026-1486
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 9, 2026
rPGP affected by crash in message handling for deeply nested messages
High
GHSA-8h58-w33p-wq3g
was published
for
pgp
(Rust)
Feb 13, 2026
rPGP vulnerable to parser crash on crafted RSA secret key packets through CVE-2026-21895
High
GHSA-7587-4wv6-m68m
was published
for
pgp
(Rust)
Feb 13, 2026
Wildfly Elytron integration susceptible to brute force attacks via CLI
High
CVE-2025-23368
was published
for
org.wildfly.core:wildfly-elytron-integration
(Maven)
Feb 13, 2026
Duplicate Advisory: Wildfly Elytron integration susceptible to brute force attacks via CLI
High
GHSA-3jxr-23ph-c89g
was published
for
org.wildfly.core:wildfly-elytron-integration
(Maven)
Mar 4, 2025
•
withdrawn
Keycloak affected by improper invitation token validation
High
CVE-2026-1529
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 9, 2026
Microsoft Security Advisory CVE-2026-21218 | .NET Security Feature Bypass Vulnerability
High
CVE-2026-21218
was published
for
System.Security.Cryptography.Cose
(NuGet)
Feb 10, 2026
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
High
CVE-2026-25757
was published
for
spree_storefront
(RubyGems)
Feb 5, 2026
Unauthenticated Spree Commerce users can access all guest addresses
High
CVE-2026-25758
was published
for
spree_api
(RubyGems)
Feb 5, 2026
Arbitrary WASM Code Execution via AnnotationOverrideFlight Injection in Yoke ATC
High
CVE-2026-26056
was published
for
github.com/yokecd/yoke
(Go)
Feb 12, 2026
Unauthenticated Admission Webhook Endpoints in Yoke ATC
High
CVE-2026-26055
was published
for
github.com/yokecd/yoke
(Go)
Feb 12, 2026
cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
High
CVE-2026-26007
was published
for
cryptography
(pip)
Feb 10, 2026
CediPay Affected by Improper Input Validation in Payment Processing
High
CVE-2026-26063
was published
for
cedipay-core
(npm)
Feb 12, 2026
MagicLink: Insecure Deserialization of MagicLink Actions Leads to Remote Code Execution
High
GHSA-r33w-fg8j-9c94
was published
for
cesargb/laravel-magiclink
(Composer)
Feb 12, 2026
Keras vulnerable to arbitrary file read in the model loading mechanism (HDF5 integration)
High
CVE-2026-1669
was published
for
keras
(pip)
Feb 12, 2026
Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls
High
CVE-2025-14874
was published
for
nodemailer
(npm)
Dec 1, 2025
Traefik: TCP readTimeout bypass via STARTTLS on Postgres
High
CVE-2026-25949
was published
for
github.com/traefik/traefik/v3
(Go)
Feb 12, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP
High
CVE-2026-24895
was published
for
github.com/dunglas/frankenphp
(Go)
Feb 12, 2026
FrankenPHP leaks session data between requests in worker mode
High
CVE-2026-24894
was published
for
github.com/dunglas/frankenphp
(Go)
Feb 12, 2026
Mattermost Server allows an attacker to specify a full pathname of a log file
High
CVE-2017-18912
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions
High
CVE-2026-1615
was published
for
jsonpath
(npm)
Feb 9, 2026
Leaky JWTs in OpenMetadata exposing highly-privileged bot users
High
CVE-2026-26010
was published
for
org.open-metadata:openmetadata-sdk
(Maven)
Feb 11, 2026
Pillow affected by out-of-bounds write when loading PSD images
High
CVE-2026-25990
was published
for
pillow
(pip)
Feb 11, 2026
Vikunja Vulnerable to XSS Via Task Preview
High
CVE-2026-25935
was published
for
code.vikunja.io/api
(Go)
Feb 11, 2026
ProTip!
Advisories are also available from the
GraphQL API