GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,876
Maven
5,000+
npm
4,502
NuGet
780
pip
4,254
Pub
12
RubyGems
975
Rust
1,100
Swift
49
Unreviewed advisories
All unreviewed
5,000+
25,627 advisories
Filter by severity
PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling
High
CVE-2026-24765
was published
for
phpunit/phpunit
(Composer)
Jan 27, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access
Moderate
CVE-2026-24748
was published
for
github.com/akuity/kargo
(Go)
Jan 27, 2026
StudioCMS has Authorization Bypass Through User-Controlled Key
Moderate
CVE-2026-24134
was published
for
studiocms
(npm)
Jan 27, 2026
PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint Files
High
CVE-2026-24747
was published
for
pytorch
(pip)
Jan 27, 2026
SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor
Critical
CVE-2026-23830
was published
for
@nyariv/sandboxjs
(npm)
Jan 27, 2026
Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
Moderate
CVE-2025-59471
was published
for
next
(npm)
Jan 27, 2026
Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)
Moderate
CVE-2026-24473
was published
for
hono
(npm)
Jan 27, 2026
hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception
Moderate
CVE-2026-24472
was published
for
hono
(npm)
Jan 27, 2026
Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing
Moderate
CVE-2026-24398
was published
for
hono
(npm)
Jan 27, 2026
OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication
Moderate
CVE-2026-23892
was published
for
OctoPrint
(pip)
Jan 27, 2026
Kyverno Denial of Service via Context Variable Amplification in Policy Engine
High
CVE-2026-23881
was published
for
github.com/kyverno/kyverno
(Go)
Jan 27, 2026
Kyverno Cross-Namespace Privilege Escalation via Policy apiCall
Critical
CVE-2026-22039
was published
for
github.com/kyverno/kyverno
(Go)
Jan 27, 2026
oneshot has potential Use After Free when used asynchronously
High
GHSA-rvr2-r3pv-5m4p
was published
for
oneshot
(Rust)
Jan 27, 2026
gmrtd ReadFile Vulnerable to Denial of Service via Excessive TLV Length Values
Moderate
CVE-2026-24738
was published
for
github.com/gmrtd/gmrtd
(Go)
Jan 27, 2026
Dozzle Agent Label-Based Access Control Bypass Allows Unauthorized Container Shell Access
High
CVE-2026-24740
was published
for
github.com/amir20/dozzle
(Go)
Jan 27, 2026
Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64
Moderate
CVE-2026-24116
was published
for
wasmtime
(Rust)
Jan 27, 2026
go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Names
Moderate
CVE-2026-24686
was published
for
github.com/theupdateframework/go-tuf/v2
(Go)
Jan 26, 2026
pypdf has possible Infinite Loop when processing outlines/bookmarks
Moderate
CVE-2026-24688
was published
for
pypdf
(pip)
Jan 26, 2026
MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
High
CVE-2026-24490
was published
for
mobsf
(pip)
Jan 26, 2026
Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCE
Critical
GHSA-cr3w-cw5w-h3fj
was published
for
@saltcorn/server
(npm)
Jan 26, 2026
Gakido vulnerable to HTTP Header Injection (CRLF Injection)
Moderate
CVE-2026-24489
was published
for
gakido
(pip)
Jan 26, 2026
Python-Multipart has Arbitrary File Write via Non-Default Configuration
High
CVE-2026-24486
was published
for
python-multipart
(pip)
Jan 26, 2026
Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName
High
CVE-2026-24470
was published
for
github.com/zalando/skipper
(Go)
Jan 26, 2026
sigstore CSRF possibility in OIDC authentication during signing
Low
CVE-2026-24408
was published
for
sigstore
(pip)
Jan 26, 2026
AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion
High
CVE-2026-24400
was published
for
org.assertj:assertj-core
(Maven)
Jan 26, 2026
ProTip!
Advisories are also available from the
GraphQL API