GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
35,755 advisories
Filter by severity
Obot: Server-Side Request Forgery via remote MCP server URL
High
GHSA-jgh3-fggc-mcpm
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Obot: MCP Registry API readable without authentication
Moderate
GHSA-pr6h-vr44-xq8j
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
High
GHSA-xwmw-prc4-v3cr
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Paymenter has a credit-refund double-spend race condition in service downgrade (doUpgrade)
Moderate
CVE-2026-71537
was published
for
paymenter/paymenter
(Composer)
Sep 18, 2026
io.moquette:moquette-broker has a Missing Authorization issue
High
CVE-2026-85058
was published
for
io.moquette:moquette-broker
(Maven)
Sep 18, 2026
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
Critical
CVE-2026-59163
was published
for
mnemosyne-memory
(pip)
Sep 18, 2026
Perses's unvalidated project parameter enables filesystem path traversal
High
CVE-2026-63445
was published
for
github.com/perses/perses
(Go)
Sep 18, 2026
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
High
CVE-2026-63199
was published
for
github.com/perses/perses
(Go)
Sep 18, 2026
Perses's project query parameter authorization bypass exposes cross-project resources
High
CVE-2026-63458
was published
for
github.com/perses/perses
(Go)
Sep 18, 2026
File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
High
CVE-2026-91127
was published
for
@file-viewer/doc
(npm)
Sep 18, 2026
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
High
CVE-2026-77301
was published
for
adm-zip
(npm)
Sep 18, 2026
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
Moderate
CVE-2026-77339
was published
for
github.com/f1bonacc1/process-compose
(Go)
Sep 18, 2026
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials
High
CVE-2026-81505
was published
for
github.com/frain-dev/convoy
(Go)
Sep 18, 2026
md-editor-v3: XSS via fenced-code language rendering bypass
Moderate
CVE-2026-84992
was published
for
md-editor-v3
(npm)
Sep 18, 2026
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets
Moderate
CVE-2026-63406
was published
for
github.com/anycable/anycable
(Go)
Sep 18, 2026
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
High
CVE-2026-63349
was published
for
anyio
(pip)
Sep 18, 2026
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
Critical
CVE-2026-63374
was published
for
anyio
(pip)
Sep 18, 2026
AnyIO process-pool workers can block indefinitely on undrained stderr
Moderate
CVE-2026-64847
was published
for
anyio
(pip)
Sep 18, 2026
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
Moderate
CVE-2026-63405
was published
for
github.com/anycable/anycable
(Go)
Sep 18, 2026
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
High
CVE-2026-58197
was published
for
github.com/stacklok/toolhive
(Go)
Sep 18, 2026
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
Critical
CVE-2026-61682
was published
for
github.com/kcp-dev/kcp
(Go)
Sep 18, 2026
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion
High
CVE-2026-61833
was published
for
zotregistry.dev/zot/v2
(Go)
Sep 18, 2026
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation
Moderate
CVE-2026-61795
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
High
CVE-2026-61672
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic
Moderate
CVE-2026-61794
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
ProTip!
Advisories are also available from the
GraphQL API