GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            267 advisories
        Filter by severity
        
      
      
    
                    
                      Liferay Portal is vulnerable to DNS rebinding attacks
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62266
                      
                      was published
                        for
                        
                          com.liferay.portal:release.portal.bom
                        
                        (Maven)
                      Oct 30, 2025 
                    
                  
                    
                      PrivateBin is missing HTML sanitization of attached filename in file size hint
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62796
                      
                      was published
                        for
                        
                          privatebin/privatebin
                        
                        (Composer)
                      Oct 28, 2025 
                    
                  
                    
                      Liferay Portal Vulnerable to Open Redirect via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameter
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62253
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.layout.admin.web
                        
                        (Maven)
                      Oct 27, 2025 
                    
                  
                    
                      Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62595
                      
                      was published
                        for
                        
                          koa
                        
                        (npm)
                      Oct 21, 2025 
                    
                  
                    
                      lobe-chat has an Open Redirect
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59426
                      
                      was published
                        for
                        
                          @lobehub/chat
                        
                        (npm)
                      Sep 24, 2025 
                    
                  
                    
                      Liferay Portal's System, Instance and Site Settings are vulnerable to Open Redirect
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-43795
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.configuration.admin.web
                        
                        (Maven)
                      Sep 12, 2025 
                    
                  
                    
                      TYPO3 CMS has an open‑redirect vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59013
                      
                      was published
                        for
                        
                          typo3/cms-core
                        
                        (Composer)
                      Sep 9, 2025 
                    
                  
                    
                      Google Sign-In for Rails allowed redirect to protocol-relative URI
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-58067
                      
                      was published
                        for
                        
                          google_sign_in
                        
                        (RubyGems)
                      Aug 29, 2025 
                    
                  
                    
                      Google Sign-In for Rails allowed redirects to malformed URLs
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-57821
                      
                      was published
                        for
                        
                          google_sign_in
                        
                        (RubyGems)
                      Aug 27, 2025 
                    
                  
                    
                      Liferay Portal allows open redirect in /c/portal/edit_info_item parameter redirect
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-43767
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.info.impl
                        
                        (Maven)
                      Aug 23, 2025 
                    
                  
                    
                      @astrojs/node's trailing slash handling causes open redirect issue
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-55207
                      
                      was published
                        for
                        
                          @astrojs/node
                        
                        (npm)
                      Aug 15, 2025 
                    
                  
                    
                      svg-sanitizer Bypasses Attribute Sanitization
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-55166
                      
                      was published
                        for
                        
                          enshrined/svg-sanitize
                        
                        (Composer)
                      Aug 12, 2025 
                    
                  
                    
                      Astros's duplicate trailing slash feature leads to an open redirection security issue
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54793
                      
                      was published
                        for
                        
                          astro
                        
                        (npm)
                      Aug 7, 2025 
                    
                  
                    
                      DiracX-Web is vulnerable to attack through an Open Redirect on its login page
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54066
                      
                      was published
                        for
                        
                          @dirac-grid/diracx-web-components
                        
                        (npm)
                      Jul 17, 2025 
                    
                  
                    
                      n8n allows open redirects via the /signin endpoint
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-49592
                      
                      was published
                        for
                        
                          n8n
                        
                        (npm)
                      Jun 27, 2025 
                    
                  
                    
                      chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
                    
                      
  Moderate
                    
                
                      
                        GHSA-vrw8-fxc6-2r93
                      
                      was published
                        for
                        
                          github.com/go-chi/chi/v5
                        
                        (Go)
                      Jun 20, 2025 
                    
                  
                    
                      urllib3 does not control redirects in browsers and Node.js
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-50182
                      
                      was published
                        for
                        
                          urllib3
                        
                        (pip)
                      Jun 18, 2025 
                    
                  
                    
                      urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-50181
                      
                      was published
                        for
                        
                          urllib3
                        
                        (pip)
                      Jun 18, 2025 
                    
                  
                    
                      WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-1440
                      
                      was published
                        for
                        
                          org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util
                        
                        (Maven)
                      Jun 2, 2025 
                    
                  
                    
                      Mautic has an Open Redirect vulnerability on user unlock path.
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-5256
                      
                      was published
                        for
                        
                          mautic/core
                        
                        (Composer)
                      May 28, 2025 
                    
                  
                    
                      Flask-AppBuilder open redirect vulnerability using HTTP host injection
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-32962
                      
                      was published
                        for
                        
                          flask-appbuilder
                        
                        (pip)
                      May 16, 2025 
                    
                  
                    
                      @cloudflare/workers-oauth-provider missing validation of redirect_uri on authorize endpoint
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-4143
                      
                      was published
                        for
                        
                          @cloudflare/workers-oauth-provider
                        
                        (npm)
                      May 1, 2025 
                    
                  
                    
                      Duplicate Advisory: @cloudflare/workers-oauth-provider missing validation of redirect_uri on authorize endpoint
                    
                      
  Moderate
                    
                
                      
                        GHSA-7cp4-jw97-3rc2
                      
                      was published
                        for
                        
                          @cloudflare/workers-oauth-provider
                        
                        (npm)
                      May 1, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      org.xwiki.platform:xwiki-platform-wysiwyg-api Open Redirect vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-32970
                      
                      was published
                        for
                        
                          org.xwiki.platform:xwiki-platform-wysiwyg-api
                        
                        (Maven)
                      Apr 29, 2025 
                    
                  
                    
                      Apache Druid vulnerable to Server-Side Request Forgery, Cross-site Scripting, Open Redirect
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-27888
                      
                      was published
                        for
                        
                          org.apache.druid:druid
                        
                        (Maven)
                      Mar 20, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API