GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
2,738 advisories
Filter by severity
Shescape: Quadratic-time denial of service in the flag-protection
High
GHSA-gm3r-q2wp-hw87
was published
for
shescape
(npm)
Jul 24, 2026
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
High
CVE-2026-14257
was published
for
brace-expansion
(npm)
Jul 24, 2026
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
High
GHSA-g5vv-q72c-7j78
was published
for
@anephenix/hub
(npm)
Jul 24, 2026
Budibase: SSRF via DNS rebinding in the REST datasource integration
High
GHSA-v42f-v8xc-j435
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
High
GHSA-pmpg-2mxq-6xwr
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
High
GHSA-pvcr-8mvp-w8qr
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
High
GHSA-2xgg-r2wc-c5r2
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
High
GHSA-qw6m-8fw2-2v64
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
High
GHSA-hr66-5mqr-8mpx
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
High
GHSA-xg5g-26x8-cvf4
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
High
GHSA-xcx6-4f2g-hhgx
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
High
GHSA-ppr4-5f46-j9c6
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
High
GHSA-c8vc-7pv3-g98p
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Privilege escalation via public role assignment API missing app-level authorization
High
GHSA-j9fc-w3mr-x6mv
was published
for
@budibase/server
(npm)
Jul 24, 2026
react-server-dom: Denial of Service in Server Functions
High
CVE-2026-44907
was published
for
react-server-dom-parcel
(npm)
Jul 24, 2026
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
High
CVE-2026-55607
was published
for
@anthropic-ai/claude-code
(npm)
Jul 24, 2026
js-yaml: Exponential parsing time in flow collections leads to denial of service
High
GHSA-pm4m-ph32-ghv5
was published
for
js-yaml
(npm)
Jul 24, 2026
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
High
GHSA-qwww-vcr4-c8h2
was published
for
react-router
(npm)
Jul 24, 2026
@fastify/static vulnerable to route guard bypass via path traversal
High
CVE-2026-15074
was published
for
@fastify/static
(npm)
Jul 24, 2026
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
High
GHSA-r28c-9q8g-f849
was published
for
postcss
(npm)
Jul 24, 2026
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
High
GHSA-qq9h-g4jm-xgf3
was published
for
better-auth
(npm)
Jul 24, 2026
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
High
GHSA-h3rm-78g3-j7cp
was published
for
@better-auth/stripe
(npm)
Jul 24, 2026
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
High
CVE-2026-55685
was published
for
react-router
(npm)
Jul 24, 2026
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
High
CVE-2026-55575
was published
for
liquidjs
(npm)
Jul 24, 2026
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
High
CVE-2026-54673
was published
for
builder-util-runtime
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API