GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
42
Go
3,114
Maven
5,000+
npm
5,000+
NuGet
826
pip
4,428
Pub
12
RubyGems
988
Rust
1,171
Swift
50
Unreviewed advisories
All unreviewed
5,000+
26,868 advisories
Filter by severity
Gogs: Release tag option injection in release deletion
High
CVE-2026-26194
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gogs: Stored XSS via data URI in issue comments
High
CVE-2026-26022
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification
Critical
CVE-2026-25921
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gokapi has privilege escalation with auth token
Moderate
CVE-2026-29060
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
Gokapi has Stored XSS in SVG Hotlinks
High
CVE-2026-28683
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
Gokapi has Data Leak in Upload Status Stream
Moderate
CVE-2026-28682
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure
Critical
CVE-2026-27944
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 5, 2026
xgrammar vulnerable to DoS via multi-layer nesting
High
CVE-2026-25048
was published
for
xgrammar
(pip)
Mar 5, 2026
Mercurius: Incorrect Content-Type parsing can lead to CSRF attack
Moderate
CVE-2025-64166
was published
for
mercurius
(npm)
Mar 5, 2026
Leantime has HTML injection through firstname and lastname fields
Moderate
GHSA-qrfh-cc86-vc8c
was published
for
leantime/leantime
(Composer)
Mar 5, 2026
Python-Markdown has an Uncaught Exception
Moderate
CVE-2025-69534
was published
for
Markdown
(pip)
Mar 5, 2026
django-allauth has an open redirect vulnerability
Moderate
CVE-2026-27982
was published
for
django-allauth
(pip)
Mar 5, 2026
AVideo: Unauthenticated PHP session store exposed to host network via published memcached port
High
CVE-2026-29093
was published
for
wwbn/avideo
(Composer)
Mar 5, 2026
Agentgateway is missing parameter sanitization in MCP to OpenAPI conversion
Moderate
CVE-2026-29791
was published
for
github.com/agentgateway/agentgateway
(Go)
Mar 5, 2026
dbt-common's commonprefix() doesn't protect against path traversal
Low
CVE-2026-29790
was published
for
dbt-common
(pip)
Mar 5, 2026
opennextjs-cloudflare has SSRF vulnerability via /cdn-cgi/ path normalization bypass
High
CVE-2026-3125
was published
for
@opennextjs/cloudflare
(npm)
Mar 5, 2026
tar has Hardlink Path Traversal via Drive-Relative Linkpath
High
CVE-2026-29786
was published
for
tar
(npm)
Mar 5, 2026
`dnp3times` was removed from crates.io due to malicious code
Critical
GHSA-xhw7-jhmp-j62j
was published
for
dnp3times
(Rust)
Mar 5, 2026
Ghost has incomplete CSRF protections around OTC use
High
CVE-2026-29784
was published
for
ghost
(npm)
Mar 5, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
Critical
GHSA-5wp8-q9mx-8jx8
was published
for
zeptoclaw
(Rust)
Mar 5, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
High
GHSA-hhjv-jq77-cmvx
was published
for
zeptoclaw
(Rust)
Mar 5, 2026
Parse Server's Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction
High
CVE-2026-29182
was published
for
parse-server
(npm)
Mar 5, 2026
pyLoad has an Arbitrary File Write via Path Traversal in edit_package()
High
CVE-2026-29778
was published
for
pyload-ng
(pip)
Mar 5, 2026
Duplicate Advisory: HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
Critical
GHSA-262p-vjx5-45xh
was published
for
pingora-core
(Rust)
Mar 5, 2026
•
withdrawn
Duplicate Advisory: HTTP Request Smuggling via Premature Upgrade
Critical
GHSA-f9v3-j2m7-4hpg
was published
for
pingora-core
(Rust)
Mar 5, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API