GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,751
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,571
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
35,573 advisories
Filter by severity
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE
High
CVE-2026-88975
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
High
CVE-2026-61544
was published
for
libp2p-quic
(Rust)
Sep 15, 2026
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators
Moderate
CVE-2026-69201
was published
for
org.http4s:http4s-server_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2: unbounded continuation frame accumulation
High
CVE-2026-69218
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: Ember chunk parser lenience (TE.TE request smuggling)
Moderate
CVE-2026-69216
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin
Moderate
CVE-2026-69215
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
Moderate
CVE-2026-69214
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2 has an unbounded outbound frame queue
High
CVE-2026-69213
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: DigestAuth nonce map grows unbounded
High
CVE-2026-69208
was published
for
org.http4s:http4s-ember-server_2.12
(Maven)
Sep 15, 2026
Http4s: DigestAuth allows replay of captured requests
Moderate
CVE-2026-69206
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)
High
CVE-2026-69205
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
Critical
CVE-2026-69204
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
High
CVE-2026-69203
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2: unbounded inbound body buffering
High
CVE-2026-69202
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
Low
GHSA-rf68-8gjr-36q7
was published
for
github.com/nezhahq/nezha
(Go)
Sep 15, 2026
Netmaker has a boolean‑based SQL Injection
Moderate
CVE-2026-32599
was published
for
github.com/gravitl/netmaker
(Go)
Sep 15, 2026
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
Moderate
CVE-2026-76081
was published
for
github.com/zitadel/zitadel
(Go)
Sep 14, 2026
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
High
CVE-2026-56668
was published
for
github.com/zitadel/zitadel
(Go)
Sep 14, 2026
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
Critical
CVE-2026-59178
was published
for
esphome-device-builder
(pip)
Sep 14, 2026
October CMS: Incomplete Scheme Validation in Image Resizer
Low
GHSA-2xmm-m4wv-3fjh
was published
for
october/october
(Composer)
Sep 14, 2026
October CMS: PHP Object Injection via Backend Widget Session Storage
Low
CVE-2026-49400
was published
for
october/system
(Composer)
Sep 14, 2026
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
Low
CVE-2026-46696
was published
for
october/system
(Composer)
Sep 14, 2026
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
Moderate
CVE-2026-56666
was published
for
github.com/zitadel/zitadel
(Go)
Sep 11, 2026
yayson: Prototype pollution in Store/LegacyStore deserialization
Critical
CVE-2026-61534
was published
for
yayson
(npm)
Sep 11, 2026
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
High
CVE-2026-59148
was published
for
@mockoon/cli
(npm)
Sep 11, 2026
ProTip!
Advisories are also available from the
GraphQL API