GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
222 advisories
Filter by severity
Meridian: Multiple defense-in-depth gaps (collection/depth caps, telemetry, retry, fan-out)
High
GHSA-f5v8-v6q3-q4h6
was published
for
Meridian.Mapping
(NuGet)
Apr 16, 2026
Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService
Moderate
CVE-2026-34164
was published
for
com.ritense.valtimo:inbox
(Maven)
Apr 16, 2026
Apache Airflow: JWT token appearing in logs
Moderate
CVE-2026-31987
was published
for
apache-airflow
(pip)
Apr 16, 2026
LangSmith SDK: Streaming token events bypass output redaction
Moderate
GHSA-rr7j-v2q5-chgv
was published
for
langsmith
(npm)
Apr 16, 2026
Oxia exposes bearer token in debug log messages on authentication failure
High
GHSA-pm7q-rjjx-979p
was published
for
github.com/oxia-db/oxia
(Go)
Apr 14, 2026
SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs
Moderate
CVE-2026-40091
was published
for
github.com/authzed/spicedb
(Go)
Apr 14, 2026
Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI
Moderate
CVE-2025-66236
was published
for
apache-airflow
(pip)
Apr 13, 2026
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
High
CVE-2026-34487
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
kube-router: BGP Peer Passwords Exposed in Logs at Verbose Logging Level
Moderate
GHSA-fcmh-qfxc-w685
was published
for
github.com/cloudnativelabs/kube-router/v2
(Go)
Apr 8, 2026
Apache Cassandra has sensitive Information Leak in cqlsh
Moderate
CVE-2026-27315
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Apr 7, 2026
Harbor: LDAP password and OIDC secret are not redacted in the audit log
Moderate
GHSA-prh4-vhfh-24mj
was published
for
github.com/goharbor/harbor
(Go)
Mar 26, 2026
OpenClaw Telegram media fetch errors exposed bot tokens in logged file URLs
Moderate
GHSA-xwcj-hwhf-h378
was published
for
openclaw
(npm)
Mar 16, 2026
OpenClaw: Pairing setup codes exposed long-lived shared gateway credentials instead of short-lived bootstrap tokens
Moderate
GHSA-7h7g-x2px-94hj
was published
for
openclaw
(npm)
Mar 13, 2026
OneUptime: Password Reset Token Logged at INFO Level
Moderate
CVE-2026-32598
was published
for
oneuptime
(npm)
Mar 13, 2026
OliveTin's email argument makes compliance harder, enables log injection
Moderate
GHSA-xx6g-43w2-9g6g
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 12, 2026
Apache ZooKeeper has improper handling of configuration values
High
CVE-2026-24308
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Mar 7, 2026
@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass
Low
CVE-2026-29184
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Mar 5, 2026
Rancher Backup Operator pod's logs leak S3 tokens
Moderate
CVE-2025-62879
was published
for
github.com/rancher/backup-restore-operator
(Go)
Mar 3, 2026
Curio exposes database credentials to users with network access through verbose HTTP error responses
High
GHSA-gj6x-q8rh-wj6x
was published
for
github.com/filecoin-project/curio
(Go)
Feb 26, 2026
Terraform Provider for Linode Debug Logs Vulnerable to Sensitive Information Exposure
Moderate
CVE-2026-27900
was published
for
github.com/linode/terraform-provider-linode
(Go)
Feb 26, 2026
Apache Airflow exposes sensitive information in its log files
Moderate
CVE-2025-27555
was published
for
apache-airflow
(pip)
Feb 24, 2026
unity-cli Exposes Plaintext Credentials in Debug Logs (sign-package command)
Moderate
CVE-2026-25918
was published
for
@rage-against-the-pixel/unity-cli
(npm)
Feb 10, 2026
Neo4j Enterprise and Community vulnerable to a potential information disclosure
Moderate
CVE-2026-1622
was published
for
org.neo4j:neo4j
(Maven)
Feb 4, 2026
RustFS Logs Sensitive Credentials in Plaintext
Moderate
CVE-2026-24762
was published
for
rustfs
(Rust)
Feb 3, 2026
ProTip!
Advisories are also available from the
GraphQL API