GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
852 advisories
Filter by severity
Spinnaker: RCE via expression parsing due to unrestricted context handling
Critical
CVE-2026-32613
was published
for
io.spinnaker.echo:echo-pipelinetriggers
(Maven)
Apr 21, 2026
Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
Critical
CVE-2026-32604
was published
for
io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo
(Maven)
Apr 21, 2026
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
Critical
CVE-2026-33557
was published
for
org.apache.kafka:kafka-clients
(Maven)
Apr 20, 2026
Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
Critical
CVE-2026-40478
was published
for
org.thymeleaf:thymeleaf
(Maven)
Apr 15, 2026
Improper restriction of the scope of accessible objects in Thymeleaf expressions
Critical
CVE-2026-40477
was published
for
org.thymeleaf:thymeleaf
(Maven)
Apr 15, 2026
Expression Injection in OpenRemote
Critical
CVE-2026-39842
was published
for
io.openremote:openremote-manager
(Maven)
Apr 14, 2026
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
Critical
CVE-2026-29145
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
Emissary has GitHub Actions Shell Injection via Workflow Inputs
Critical
CVE-2026-35580
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 8, 2026
OpenIdentityPlatform OpenAM: Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM
Critical
CVE-2026-33439
was published
for
org.openidentityplatform.openam:openam
(Maven)
Apr 7, 2026
FHIR Validator HTTP service has SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft
Critical
CVE-2026-34361
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.validation
(Maven)
Mar 30, 2026
Spring AI: SpEL injection is triggered when a user-supplied value is used as a filter expression key
Critical
CVE-2026-22738
was published
for
org.springframework.ai:spring-ai-vector-store
(Maven)
Mar 27, 2026
splunk-otel-javaagent: Unsafe deserialization in RMI instrumentation may lead to Remote Code Execution
Critical
GHSA-h8w2-rv57-vc6f
was published
for
com.splunk:splunk-otel-javaagent
(Maven)
Mar 26, 2026
dd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code execution
Critical
CVE-2026-33728
was published
for
com.datadoghq:dd-java-agent
(Maven)
Mar 26, 2026
OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution
Critical
CVE-2026-33701
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Mar 25, 2026
Spring Security HTTP Headers Are not Written Under Some Conditions
Critical
CVE-2026-22732
was published
for
org.springframework.security:spring-security-web
(Maven)
Mar 20, 2026
HAPI FHIR HTTP authentication leak in redirects
Critical
CVE-2026-33180
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.convertors
(Maven)
Mar 18, 2026
Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames
Critical
CVE-2026-25534
was published
for
io.spinnaker.clouddriver:clouddriver-artifacts
(Maven)
Mar 16, 2026
Apache IoTDB has an Insecure Default Configuration Vulnerability
Critical
CVE-2026-24015
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Mar 9, 2026
Apache IoTDB has an Improper Input Validation vulnerability
Critical
CVE-2026-24713
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Mar 9, 2026
pac4j-jwt: JwtAuthenticator Authentication Bypass via JWE-Wrapped PlainJWT
Critical
CVE-2026-29000
was published
for
org.pac4j:pac4j-jwt
(Maven)
Mar 5, 2026
Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions
Critical
CVE-2026-27446
was published
for
org.apache.activemq:artemis-server
(Maven)
Mar 4, 2026
Apache Ranger has a Code Injection vulnerability
Critical
CVE-2025-59059
was published
for
org.apache.ranger:ranger-plugins-common
(Maven)
Mar 3, 2026
Apache Camel: KeycloakSecurityPolicy does not validate issuer of JWT tokens against configured realm
Critical
CVE-2026-23552
was published
for
org.apache.camel:camel-keycloak
(Maven)
Feb 23, 2026
carbon-apimgt does not properly restrict uploaded files
Critical
CVE-2025-13590
was published
for
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl
(Maven)
Feb 19, 2026
Apache Druid Vulnerable to Authentication Bypass
Critical
CVE-2026-23906
was published
for
org.apache.druid.extensions:druid-basic-security
(Maven)
Feb 10, 2026
ProTip!
Advisories are also available from the
GraphQL API