GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,771
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
35,711 advisories
Filter by severity
Grav CMS vulnerable to remote code execution via .zip file upload
High
CVE-2026-72819
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
High
CVE-2026-75837
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate
Moderate
CVE-2026-75834
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write
Critical
CVE-2026-75827
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
Critical
CVE-2026-75828
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
High
CVE-2026-74907
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
High
CVE-2026-72695
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
High
CVE-2026-86003
was published
for
github.com/coredns/coredns
(Go)
Sep 17, 2026
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
Moderate
CVE-2026-86000
was published
for
soupsieve
(pip)
Sep 17, 2026
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
Moderate
CVE-2026-85999
was published
for
soupsieve
(pip)
Sep 17, 2026
@platejs/core HTML deserialization can trigger browser behavior during parsing
Moderate
CVE-2026-88976
was published
for
@platejs/core
(npm)
Sep 17, 2026
react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU
High
CVE-2026-84997
was published
for
react/http
(Composer)
Sep 17, 2026
CoreDNS: Unauthenticated memory exhaustion in custom transports
High
CVE-2026-82399
was published
for
github.com/coredns/coredns
(Go)
Sep 17, 2026
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
High
CVE-2026-81876
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.r5
(Maven)
Sep 17, 2026
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
High
CVE-2026-81875
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.r5
(Maven)
Sep 17, 2026
djust: A template binding inherits a context safety grant it never earned (XSS)
High
GHSA-xjw9-38cr-6372
was published
for
djust
(pip)
Sep 17, 2026
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
High
GHSA-9395-2g46-rj3f
was published
for
djust
(pip)
Sep 17, 2026
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Moderate
CVE-2026-81871
was published
for
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc
(Go)
Sep 17, 2026
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low
CVE-2026-81870
was published
for
go.opentelemetry.io/otel/exporters/otlp/otlptrace
(Go)
Sep 17, 2026
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
Moderate
CVE-2026-81868
was published
for
Steeltoe.Security.Authorization.Certificate
(NuGet)
Sep 17, 2026
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
High
CVE-2026-81516
was published
for
Steeltoe.Discovery.Consul
(NuGet)
Sep 17, 2026
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
High
CVE-2026-81515
was published
for
Steeltoe.Discovery.Eureka
(NuGet)
Sep 17, 2026
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
High
CVE-2026-86049
was published
for
jupyter_server
(pip)
Sep 17, 2026
Svelte devalue: DoS via malformed input
Moderate
CVE-2026-81176
was published
for
devalue
(npm)
Sep 17, 2026
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
Critical
CVE-2026-79752
was published
for
cakephp/cakephp
(Composer)
Sep 17, 2026
ProTip!
Advisories are also available from the
GraphQL API