GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
3,990
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,390
Swift
56
Unreviewed advisories
All unreviewed
5,000+
44 advisories
Filter by severity
@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters
High
CVE-2026-44974
was published
for
@hapi/content
(npm)
May 27, 2026
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
High
CVE-2026-42462
was published
for
@fedify/fedify
(npm)
May 26, 2026
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
High
CVE-2026-6322
was published
for
fast-uri
(npm)
May 8, 2026
A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server...
High
Unreviewed
CVE-2026-8034
was published
May 8, 2026
Flight: HTTP method override enabled by default, facilitating CSRF escalation and middleware bypass
High
CVE-2026-42551
was published
for
flightphp/core
(Composer)
May 6, 2026
Heimdall has an authorization bypass via path normalization mismatch
High
CVE-2026-42274
was published
for
github.com/dadrus/heimdall
(Go)
Apr 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass
High
CVE-2026-42273
was published
for
github.com/dadrus/heimdall
(Go)
Apr 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation
High
CVE-2026-42272
was published
for
github.com/dadrus/heimdall
(Go)
Apr 25, 2026
@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
High
CVE-2026-33804
was published
for
@fastify/middie
(npm)
Apr 16, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk
High
GHSA-q382-vc8q-7jhj
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Mar 19, 2026
OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv
High
CVE-2026-32971
was published
for
openclaw
(npm)
Mar 13, 2026
SEPPmail Secure Email Gateway before version 15.0.1 incorrectly interprets email addresses in the...
High
Unreviewed
CVE-2026-27444
was published
Mar 4, 2026
MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity
High
CVE-2026-27896
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Feb 26, 2026
Fickling: OBJ opcode call invisibility bypasses all safety checks
High
GHSA-mxhj-88fx-4pcv
was published
for
fickling
(pip)
Feb 24, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18...
High
Unreviewed
CVE-2026-0958
was published
Feb 11, 2026
Fastify's Content-Type header tab character allows body validation bypass
High
CVE-2026-25223
was published
for
fastify
(npm)
Feb 2, 2026
node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization
High
CVE-2025-12816
was published
for
node-forge
(npm)
Nov 26, 2025
Duplicate Advisory: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
High
GHSA-jj37-3377-m6vv
was published
for
nodemailer
(npm)
Nov 14, 2025
•
withdrawn
RatPanel can perform remote command execution without authorization
High
CVE-2025-53534
was published
for
github.com/tnborg/panel
(Go)
Aug 4, 2025
Git LFS permits exfiltration of credentials via crafted HTTP URLs
High
CVE-2024-53263
was published
for
github.com/git-lfs/git-lfs
(Go)
Jan 14, 2025
Git Credential Manager carriage-return character in remote URL allows malicious repository to leak credentials
High
CVE-2024-50338
was published
for
git-credential-manager
(NuGet)
Jan 14, 2025
Name confusion in x509 Subject Alternative Name fields
High
CVE-2023-52892
was published
for
phpseclib/phpseclib
(Composer)
Jun 28, 2024
Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its use of MIME-tools, has an...
High
Unreviewed
CVE-2024-28054
was published
Mar 18, 2024
A interpretation conflict in Fortinet IPS Engine versions 7.321, 7.166 and 6.158 allows attacker...
High
Unreviewed
CVE-2023-40718
was published
Oct 10, 2023
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions...
High
Unreviewed
CVE-2023-32708
was published
Jul 6, 2023
ProTip!
Advisories are also available from the
GraphQL API