GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
2,473 advisories
Filter by severity
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
Moderate
GHSA-8q49-2h5h-434x
was published
for
@frontmcp/adapters
(npm)
Jul 24, 2026
Quasar: Prototype pollution in the extend() utility
Moderate
GHSA-3r53-75j5-3g7j
was published
for
quasar
(npm)
Jul 24, 2026
Shescape: Home-directory disclosure in assignment context on Unix with Dash
Moderate
GHSA-q53c-4prm-w95q
was published
for
shescape
(npm)
Jul 24, 2026
Shescape: Path disclosure on Unix with Zsh
Moderate
GHSA-6v4m-fw66-8r4x
was published
for
shescape
(npm)
Jul 24, 2026
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
Moderate
GHSA-hfhx-w8p8-4hc7
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Account Enumeration via Login Lockout Response Differential
Moderate
GHSA-cr7p-cr3q-h5cm
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
Moderate
GHSA-gh4h-34gr-87r7
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
Moderate
GHSA-fcrw-f7gg-6g9f
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
Moderate
GHSA-4qcj-m5wp-jmf4
was published
for
@budibase/server
(npm)
Jul 24, 2026
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
Moderate
CVE-2026-7120
was published
for
@fastify/static
(npm)
Jul 24, 2026
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Moderate
GHSA-r292-9mhp-454m
was published
for
tar
(npm)
Jul 24, 2026
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
Moderate
GHSA-664h-wqgq-64gw
was published
for
mongoose
(npm)
Jul 24, 2026
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
Moderate
GHSA-38hq-7x33-php4
was published
for
@backstage/plugin-auth-backend
(npm)
Jul 24, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
Moderate
GHSA-53g2-mvcc-q9x3
was published
for
action_text-trix
(RubyGems)
Jul 24, 2026
Valibot: record() issue paths can make flatten() throw for inherited Object property names
Moderate
CVE-2026-59952
was published
for
valibot
(npm)
Jul 24, 2026
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
Moderate
GHSA-866w-xmhq-wj7x
was published
for
@sveltejs/kit
(npm)
Jul 24, 2026
SvelteKit: Big remote form function payloads can cause Node process to crash
Moderate
GHSA-wqjv-9729-c5q2
was published
for
@sveltejs/kit
(npm)
Jul 24, 2026
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
Moderate
CVE-2026-53669
was published
for
react-router
(npm)
Jul 23, 2026
React Router: Open redirect leading to XSS
Moderate
CVE-2026-53668
was published
for
react-router
(npm)
Jul 23, 2026
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
Moderate
CVE-2026-53667
was published
for
react-router
(npm)
Jul 23, 2026
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
Moderate
CVE-2026-53666
was published
for
react-router
(npm)
Jul 23, 2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Moderate
GHSA-x445-f3h2-j279
was published
for
@auth/core
(npm)
Jul 23, 2026
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
Moderate
GHSA-652q-gvq3-74qv
was published
for
n8n
(npm)
Jul 22, 2026
n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
Moderate
GHSA-jqwr-vx3p-r266
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
Moderate
GHSA-9cmh-xcqm-5hqr
was published
for
n8n
(npm)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API