GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
57
GitHub Actions
50
Go
3,767
Maven
5,000+
npm
5,000+
NuGet
937
pip
4,999
Pub
13
RubyGems
1,058
Rust
1,347
Swift
54
Unreviewed advisories
All unreviewed
5,000+
16 advisories
Filter by severity
@isaacs/brace-expansion has Uncontrolled Resource Consumption
High
CVE-2026-25547
was published
for
@isaacs/brace-expansion
(npm)
Feb 3, 2026
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
High
CVE-2026-23745
was published
for
tar
(npm)
Jan 16, 2026
tar has Hardlink Path Traversal via Drive-Relative Linkpath
High
CVE-2026-29786
was published
for
tar
(npm)
Mar 5, 2026
node-tar Symlink Path Traversal via Drive-Relative Linkpath
High
CVE-2026-31802
was published
for
tar
(npm)
Mar 10, 2026
@stablelib/cbor: Stack exhaustion Denial of Service via deeply nested CBOR arrays, maps, or tags
High
GHSA-5jg4-p4qw-cgfr
was published
for
@stablelib/cbor
(npm)
Apr 4, 2026
@stablelib/cbor: Prototype poisoning via `__proto__` map keys in CBOR decoding
High
GHSA-w48f-fwg7-ww6p
was published
for
@stablelib/cbor
(npm)
Apr 4, 2026
LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates
High
CVE-2026-35525
was published
for
liquidjs
(npm)
Apr 8, 2026
unhead: Streaming SSR `streamKey` injected into inline script without identifier validation
Low
GHSA-x7mm-9vvv-64w8
was published
for
unhead
(npm)
Apr 10, 2026
In monetr, unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation
High
CVE-2026-40481
was published
for
github.com/monetr/monetr
(Go)
Apr 14, 2026
quarkus-openapi-generator has overly broad path-parameter matching that sends authentication headers to unintended operations
Moderate
CVE-2026-42333
was published
for
io.quarkiverse.openapi.generator:quarkus-openapi-generator
(Maven)
May 4, 2026
Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME
High
CVE-2026-41211
was published
for
vite-plus
(npm)
Apr 16, 2026
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests
Moderate
CVE-2026-44456
was published
for
hono
(npm)
May 6, 2026
fast-uri vulnerable to path traversal via percent-encoded dot segments
High
CVE-2026-6321
was published
for
fast-uri
(npm)
May 8, 2026
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
High
CVE-2026-6322
was published
for
fast-uri
(npm)
May 8, 2026
xmldom has XML node injection through unvalidated comment serialization
High
CVE-2026-41672
was published
for
@xmldom/xmldom
(npm)
Apr 22, 2026
xmldom: Uncontrolled recursion in XML serialization leads to DoS
High
CVE-2026-41673
was published
for
@xmldom/xmldom
(npm)
Apr 22, 2026
ProTip!
Advisories are also available from the
GraphQL API