GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
22 advisories
Filter by severity
Moderate severity vulnerability that affects org.apache.karaf:apache-karaf
Moderate
CVE-2016-8750
was published
for
org.apache.karaf:apache-karaf
(Maven)
Jan 7, 2019
OneDev is a development operations platform. If the LDAP external authentication mechanism is...
Moderate
Unreviewed
CVE-2021-32651
was published
May 24, 2022
IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated...
Moderate
Unreviewed
CVE-2019-4297
was published
May 24, 2022
Improper neutralization of special elements used in an LDAP query ('LDAP Injection')...
Moderate
Unreviewed
CVE-2022-45910
was published
Dec 7, 2022
A vulnerability, which was classified as problematic, has been found in Jahastech NxFilter 4.3.2...
Moderate
Unreviewed
CVE-2023-6905
was published
Dec 18, 2023
NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection....
Moderate
Unreviewed
CVE-2023-31025
was published
Jan 12, 2024
Apache Zeppelin: LDAP search filter query Injection Vulnerability
Moderate
CVE-2024-31867
was published
for
org.apache.zeppelin:zeppelin-server
(Maven)
Apr 9, 2024
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP...
Moderate
Unreviewed
CVE-2018-5730
was published
May 13, 2022
The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an...
Moderate
Unreviewed
CVE-2025-27631
was published
Mar 25, 2025
Mattermost allows authenticated administrator to execute LDAP search filter injection
Moderate
CVE-2025-4573
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 11, 2025
CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated...
Moderate
Unreviewed
CVE-2025-35431
was published
Sep 17, 2025
Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction
Moderate
CVE-2026-31828
was published
for
parse-server
(npm)
Mar 11, 2026
n8n Vulnerable to LDAP Filter Injection in LDAP Node
Moderate
CVE-2026-33751
was published
for
n8n
(npm)
Mar 26, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted...
Moderate
Unreviewed
CVE-2026-29131
was published
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted...
Moderate
Unreviewed
CVE-2026-29138
was published
Apr 2, 2026
Bouncy Castle has an LDAP injection
Moderate
CVE-2026-0636
was published
for
org.bouncycastle:bcprov-jdk14
(Maven)
Apr 17, 2026
Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform...
Moderate
Unreviewed
CVE-2026-33609
was published
Apr 22, 2026
An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated...
Moderate
Unreviewed
CVE-2026-44063
was published
May 21, 2026
mitmproxy has an LDAP Injection
Moderate
CVE-2026-40606
was published
for
mitmproxy
(pip)
Apr 14, 2026
Yamcs Vulnerable to LDAP Injection in LdapAuthModule
Moderate
CVE-2026-42568
was published
for
org.yamcs:yamcs-core
(Maven)
May 26, 2026
OpenBao: LDAPi ldaputil (wrong escape func)
Moderate
CVE-2026-55770
was published
for
github.com/openbao/openbao
(Go)
Jun 19, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
Moderate
CVE-2026-46745
was published
for
apache-airflow-providers-fab
(pip)
May 26, 2026
ProTip!
Advisories are also available from the
GraphQL API