GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,410
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,502
Swift
61
Unreviewed advisories
All unreviewed
5,000+
61 advisories
Filter by severity
Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability
High
CVE-2026-47303
was published
for
Microsoft.AspNetCore.Authentication.Negotiate
(NuGet)
Jul 21, 2026
Improper neutralization of special elements used in an LDAP query ('LDAP injection')...
High
Unreviewed
CVE-2026-4256
was published
Jul 9, 2026
Improper neutralization of special elements used in an LDAP query ('LDAP injection')...
High
Unreviewed
CVE-2026-13696
was published
Jul 7, 2026
OpenAM Authentication Bypass via MSISDN LDAP Injection
High
CVE-2026-46619
was published
for
org.openidentityplatform.openam:openam-auth-msisdn
(Maven)
Jun 26, 2026
Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building...
Low
Unreviewed
CVE-2026-57288
was published
Jun 24, 2026
OpenBao: LDAPi ldaputil (wrong escape func)
Moderate
CVE-2026-55770
was published
for
github.com/openbao/openbao
(Go)
Jun 19, 2026
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
High
CVE-2026-49268
was published
for
org.apache.shiro:shiro-core
(Maven)
Jun 17, 2026
Yamcs Vulnerable to LDAP Injection in LdapAuthModule
Moderate
CVE-2026-42568
was published
for
org.yamcs:yamcs-core
(Maven)
May 26, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
Moderate
CVE-2026-46745
was published
for
apache-airflow-providers-fab
(pip)
May 26, 2026
Apache CXF has an LDAP injection vulnerability
Critical
CVE-2026-44930
was published
for
org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap
(Maven)
May 26, 2026
An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated...
Moderate
Unreviewed
CVE-2026-44063
was published
May 21, 2026
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')...
Critical
Unreviewed
CVE-2026-41919
was published
May 19, 2026
ZITADEL has LDAP Filter Injection in Login Flow
High
CVE-2026-44671
was published
for
github.com/zitadel/zitadel
(Go)
May 8, 2026
Lemur: LDAP Filter Injection enables post-authentication privilege escalation
High
CVE-2026-44304
was published
for
lemur
(pip)
May 6, 2026
Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform...
Moderate
Unreviewed
CVE-2026-33609
was published
Apr 22, 2026
Bouncy Castle has an LDAP injection
Moderate
CVE-2026-0636
was published
for
org.bouncycastle:bcprov-jdk14
(Maven)
Apr 17, 2026
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can...
High
Unreviewed
CVE-2026-40459
was published
Apr 17, 2026
mitmproxy has an LDAP Injection
Moderate
CVE-2026-40606
was published
for
mitmproxy
(pip)
Apr 14, 2026
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username
High
CVE-2026-40193
was published
for
github.com/foxcpp/maddy
(Go)
Apr 13, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted...
Moderate
Unreviewed
CVE-2026-29138
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted...
Moderate
Unreviewed
CVE-2026-29131
was published
Apr 2, 2026
If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP...
Low
Unreviewed
CVE-2026-27860
was published
Mar 27, 2026
n8n Vulnerable to LDAP Filter Injection in LDAP Node
Moderate
CVE-2026-33751
was published
for
n8n
(npm)
Mar 26, 2026
Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction
Moderate
CVE-2026-31828
was published
for
parse-server
(npm)
Mar 11, 2026
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP...
High
Unreviewed
CVE-2026-25560
was published
Feb 8, 2026
ProTip!
Advisories are also available from the
GraphQL API