GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
33,868 advisories
Filter by severity
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
Critical
GHSA-f25v-x6vr-962g
was published
for
pheditor/pheditor
(Composer)
Jul 24, 2026
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
High
CVE-2026-14257
was published
for
brace-expansion
(npm)
Jul 24, 2026
swift-nio-http2: Missing CR/LF/NUL validation in header values
Moderate
CVE-2026-64785
was published
for
swift-nio-http2
(Swift)
Jul 24, 2026
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
Critical
GHSA-vh45-f885-3848
was published
for
sm-crypto
(npm)
Jul 24, 2026
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Moderate
GHSA-v6w6-358x-2433
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
High
GHSA-47w6-gwp4-w6vc
was published
for
vantage6
(pip)
Jul 24, 2026
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
Low
GHSA-2625-rw7m-5q5x
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
Moderate
GHSA-qqc3-94qv-7fw3
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
Moderate
GHSA-f45q-w629-wr25
was published
for
hubuum_client
(Rust)
Jul 24, 2026
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
High
GHSA-26gq-p25f-99cp
was published
for
github.com/fatedier/frp
(Go)
Jul 24, 2026
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
High
GHSA-g5vv-q72c-7j78
was published
for
@anephenix/hub
(npm)
Jul 24, 2026
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
Moderate
GHSA-c534-2w9c-x7fm
was published
for
github.com/zxh326/kite
(Go)
Jul 24, 2026
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
GHSA-p279-2cqp-84jg
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Critical
GHSA-68r5-9hpg-7qw9
was published
for
org.openidentityplatform.opendj:opendj-dsml-servlet
(Maven)
Jul 24, 2026
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
High
GHSA-g3hq-hphg-8fhh
was published
for
pheditor/pheditor
(Composer)
Jul 24, 2026
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
High
GHSA-94p4-4cq8-9g67
was published
for
GitPython
(pip)
Jul 24, 2026
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
Moderate
GHSA-hfhx-w8p8-4hc7
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: SSRF via DNS rebinding in the REST datasource integration
High
GHSA-v42f-v8xc-j435
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
High
GHSA-pmpg-2mxq-6xwr
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Account Enumeration via Login Lockout Response Differential
Moderate
GHSA-cr7p-cr3q-h5cm
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
High
GHSA-pvcr-8mvp-w8qr
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
High
GHSA-2xgg-r2wc-c5r2
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
High
GHSA-qw6m-8fw2-2v64
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
Moderate
GHSA-gh4h-34gr-87r7
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
High
GHSA-hr66-5mqr-8mpx
was published
for
@budibase/server
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API