GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
14,775 advisories
Filter by severity
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
Moderate
GHSA-8q49-2h5h-434x
was published
for
@frontmcp/adapters
(npm)
Jul 24, 2026
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
Moderate
GHSA-jpcw-4wr7-c3vq
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
Quasar: Prototype pollution in the extend() utility
Moderate
GHSA-3r53-75j5-3g7j
was published
for
quasar
(npm)
Jul 24, 2026
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Moderate
GHSA-fwjx-9p69-h25h
was published
for
github.com/jandedobbeleer/oh-my-posh
(Go)
Jul 24, 2026
Shescape: Home-directory disclosure in assignment context on Unix with Dash
Moderate
GHSA-q53c-4prm-w95q
was published
for
shescape
(npm)
Jul 24, 2026
Shescape: Path disclosure on Unix with Zsh
Moderate
GHSA-6v4m-fw66-8r4x
was published
for
shescape
(npm)
Jul 24, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
Moderate
GHSA-86cx-wwf4-phq4
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
Moderate
GHSA-p6ph-3jx2-3337
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
swift-nio-http2: Missing CR/LF/NUL validation in header values
Moderate
CVE-2026-64785
was published
for
swift-nio-http2
(Swift)
Jul 24, 2026
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Moderate
GHSA-v6w6-358x-2433
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
Moderate
GHSA-qqc3-94qv-7fw3
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
Moderate
GHSA-f45q-w629-wr25
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
Moderate
GHSA-c534-2w9c-x7fm
was published
for
github.com/zxh326/kite
(Go)
Jul 24, 2026
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
Moderate
GHSA-hfhx-w8p8-4hc7
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Account Enumeration via Login Lockout Response Differential
Moderate
GHSA-cr7p-cr3q-h5cm
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
Moderate
GHSA-gh4h-34gr-87r7
was published
for
@budibase/server
(npm)
Jul 24, 2026
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
Moderate
CVE-2026-62323
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
Moderate
GHSA-fcrw-f7gg-6g9f
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
Moderate
GHSA-4qcj-m5wp-jmf4
was published
for
@budibase/server
(npm)
Jul 24, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
Moderate
CVE-2026-62280
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jul 24, 2026
Open WebUI: Arena task endpoints can bypass underlying model access controls
Moderate
CVE-2026-59225
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Moderate
CVE-2026-59212
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Moderate
CVE-2026-59223
was published
for
open-webui
(pip)
Jul 24, 2026
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
Moderate
CVE-2026-57497
was published
for
github.com/quic-go/webtransport-go
(Go)
Jul 24, 2026
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
Moderate
CVE-2026-55499
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API