GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
117
GitHub Actions
55
Go
4,836
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,577
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
35,905 advisories
Filter by severity
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
High
CVE-2026-56669
was published
for
elysia
(npm)
Sep 23, 2026
ReactPress has SQL injection via dynamic column names in TypeORM query builders
High
CVE-2026-61685
was published
for
@fecommunity/reactpress
(npm)
Sep 23, 2026
plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length
Moderate
GHSA-8pcw-h6w9-h46g
was published
for
plone.app.contenttypes
(pip)
Sep 23, 2026
plone.app.dexterity has a Denial of Service due to excessive title or description length
Moderate
CVE-2026-57576
was published
for
plone.app.dexterity
(pip)
Sep 23, 2026
OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget
High
CVE-2026-77394
was published
for
@openc3/vue-common
(npm)
Sep 23, 2026
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS
High
CVE-2026-82407
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery
High
CVE-2026-82409
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace
High
CVE-2026-82406
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Formie: Missing authorization on sent notification resend modal exposes submission PII
High
CVE-2026-76089
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Jawn: Quadratic parsing effort in AsyncParser
High
CVE-2026-61814
was published
for
org.typelevel:jawn-parser_2.12
(Maven)
Sep 23, 2026
Jawn: Uncontrolled nesting depth in JSON parser
High
CVE-2026-59990
was published
for
org.typelevel:jawn-parser_2.12
(Maven)
Sep 23, 2026
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller
High
CVE-2026-82405
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)
High
CVE-2026-86065
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: /log controls global node logging
High
CVE-2026-86064
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
Moderate
CVE-2026-93421
was published
for
mesop
(pip)
Sep 23, 2026
OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites)
Critical
CVE-2026-77602
was published
for
openc3
(RubyGems)
Sep 23, 2026
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting
High
CVE-2026-77601
was published
for
openc3
(RubyGems)
Sep 23, 2026
Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup() crashes any protobuf-decoding service
High
CVE-2026-61695
was published
for
github.com/square/wire
(Swift)
Sep 23, 2026
Formie: Unauthenticated users can overwrite incomplete submissions via submit action
High
CVE-2026-76087
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials
High
CVE-2026-76086
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated)
Moderate
CVE-2026-92692
was published
for
sulu/sulu
(Composer)
Sep 23, 2026
JLine: ReDoS in Nano Editor Regex Search Mode
Moderate
CVE-2026-77421
was published
for
org.jline:jline-builtins
(Maven)
Sep 23, 2026
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping
High
CVE-2026-77422
was published
for
org.jline:jline-builtins
(Maven)
Sep 23, 2026
9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
High
CVE-2026-56679
was published
for
9router
(npm)
Sep 23, 2026
9router: Kiro region injection allows authenticated SSRF with Authorization header forwarding
Moderate
CVE-2026-56678
was published
for
9router
(npm)
Sep 23, 2026
ProTip!
Advisories are also available from the
GraphQL API