GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
31,043 advisories
Filter by severity
Twig: Sandbox property and method bypass via object-destructuring assignment
High
CVE-2026-46639
was published
for
twig/twig
(Composer)
May 21, 2026
Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
Moderate
CVE-2026-46638
was published
for
twig/twig
(Composer)
May 21, 2026
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
Low
CVE-2026-46637
was published
for
twig/cssinliner-extra
(Composer)
May 21, 2026
Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
Low
CVE-2026-46635
was published
for
twig/twig
(Composer)
May 21, 2026
Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
Moderate
CVE-2026-46634
was published
for
twig/twig
(Composer)
May 21, 2026
Twig: PHP code injection via `{% use %}` template name
Critical
CVE-2026-46633
was published
for
twig/twig
(Composer)
May 21, 2026
twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments
Low
CVE-2026-46629
was published
for
twig/intl-extra
(Composer)
May 21, 2026
Twig: The `spaceless` filter implicitly marks its output as safe
Low
CVE-2026-46628
was published
for
twig/twig
(Composer)
May 21, 2026
JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
High
CVE-2026-46625
was published
for
js-cookie
(npm)
May 21, 2026
Russh: Unchecked CryptoVec allocation and growth handling is reachable
High
CVE-2026-46673
was published
for
russh
(Rust)
May 21, 2026
@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails
High
GHSA-59f3-7227-wmh4
was published
for
@hulumi/policies
(npm)
May 21, 2026
@hulumi/policies: GitHub OIDC trust policy bypass via AWS set-qualified condition operators
Critical
GHSA-q2f7-m237-v562
was published
for
@hulumi/policies
(npm)
May 21, 2026
@hulumi/policies: CIS 1.16 admin policy bypass for inline and attached IAM policies
High
GHSA-4xrh-5m3m-328w
was published
for
@hulumi/policies
(npm)
May 21, 2026
@hulumi/policies: HULUMI-H1 SecureBucket parent spoof bypass
High
GHSA-g43v-9x7q-83pq
was published
for
@hulumi/policies
(npm)
May 21, 2026
@hulumi/drift: Orphan reconciler accepted externally supplied execute plans
High
GHSA-2ffm-hxrq-qqmm
was published
for
@hulumi/drift
(npm)
May 21, 2026
@hulumi/baseline: CloudTrail selector tampering events were not fully detected
Moderate
GHSA-gfp8-mp24-5vxg
was published
for
@hulumi/baseline
(npm)
May 21, 2026
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
Moderate
CVE-2026-46609
was published
for
Umbraco.Cms
(NuGet)
May 21, 2026
FlaskBB: SSRF in get_image_info() via unrestricted avatar URL
Moderate
CVE-2026-46556
was published
for
flaskbb
(pip)
May 21, 2026
NocoDB: Stale Auth Cache After API Token Deletion
Low
CVE-2026-46554
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Attachment Size Limit Bypass via Upload-by-URL
Low
CVE-2026-46553
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
Moderate
CVE-2026-46552
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
Moderate
CVE-2026-46551
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags
Moderate
CVE-2026-46550
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
Low
CVE-2026-46549
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
Moderate
CVE-2026-46548
was published
for
nocodb
(npm)
May 21, 2026
ProTip!
Advisories are also available from the
GraphQL API