GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            11 advisories
        Filter by severity
        
      
      
    
                    
                      on-headers is vulnerable to http response header manipulation
                    
                      
  Low
                    
                
                      
                        CVE-2025-7339
                      
                      was published
                        for
                        
                          on-headers
                        
                        (npm)
                      Jul 17, 2025 
                    
                  
                    
                      Multer vulnerable to Denial of Service via unhandled exception from malformed request
                    
                      
  High
                    
                
                      
                        CVE-2025-7338
                      
                      was published
                        for
                        
                          multer
                        
                        (npm)
                      Jul 17, 2025 
                    
                  
                    
                      Multer vulnerable to Denial of Service via unhandled exception
                    
                      
  High
                    
                
                      
                        CVE-2025-48997
                      
                      was published
                        for
                        
                          multer
                        
                        (npm)
                      Jun 5, 2025 
                    
                  
                    
                      Multer vulnerable to Denial of Service from maliciously crafted requests
                    
                      
  High
                    
                
                      
                        CVE-2025-47944
                      
                      was published
                        for
                        
                          multer
                        
                        (npm)
                      May 19, 2025 
                    
                  
                    
                      Multer vulnerable to Denial of Service via memory leaks from unclosed streams
                    
                      
  High
                    
                
                      
                        CVE-2025-47935
                      
                      was published
                        for
                        
                          multer
                        
                        (npm)
                      May 19, 2025 
                    
                  
                    
                      basic-auth-connect's callback uses time unsafe string comparison
                    
                      
  High
                    
                
                      
                        CVE-2024-47178
                      
                      was published
                        for
                        
                          basic-auth-connect
                        
                        (npm)
                      Sep 30, 2024 
                    
                  
                    
                      send vulnerable to template injection that can lead to XSS
                    
                      
  Low
                    
                
                      
                        CVE-2024-43799
                      
                      was published
                        for
                        
                          send
                        
                        (npm)
                      Sep 10, 2024 
                    
                  
                    
                      serve-static vulnerable to template injection that can lead to XSS
                    
                      
  Low
                    
                
                      
                        CVE-2024-43800
                      
                      was published
                        for
                        
                          serve-static
                        
                        (npm)
                      Sep 10, 2024 
                    
                  
                    
                      express vulnerable to XSS via response.redirect()
                    
                      
  Low
                    
                
                      
                        CVE-2024-43796
                      
                      was published
                        for
                        
                          express
                        
                        (npm)
                      Sep 10, 2024 
                    
                  
                    
                      body-parser vulnerable to denial of service when url encoding is enabled
                    
                      
  High
                    
                
                      
                        CVE-2024-45590
                      
                      was published
                        for
                        
                          body-parser
                        
                        (npm)
                      Sep 10, 2024 
                    
                  
                    
                      Express.js Open Redirect in malformed URLs
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-29041
                      
                      was published
                        for
                        
                          express
                        
                        (npm)
                      Mar 25, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API