GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
33,868 advisories
Filter by severity
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
Critical
GHSA-mqhr-6j6h-74p5
was published
for
@budibase/server
(npm)
Jul 24, 2026
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
Moderate
CVE-2026-62323
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
Critical
GHSA-hp6v-6jw7-gv2f
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
High
GHSA-xg5g-26x8-cvf4
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
High
GHSA-xcx6-4f2g-hhgx
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
High
GHSA-ppr4-5f46-j9c6
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: SQL Injection via `multipleStatements: true`
Critical
GHSA-q6x4-v3qx-85qw
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
High
GHSA-c8vc-7pv3-g98p
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
Moderate
GHSA-fcrw-f7gg-6g9f
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
Moderate
GHSA-4qcj-m5wp-jmf4
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Privilege escalation via public role assignment API missing app-level authorization
High
GHSA-j9fc-w3mr-x6mv
was published
for
@budibase/server
(npm)
Jul 24, 2026
react-server-dom: Denial of Service in Server Functions
High
CVE-2026-44907
was published
for
react-server-dom-parcel
(npm)
Jul 24, 2026
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
Critical
CVE-2026-62379
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Jul 24, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
Moderate
CVE-2026-62280
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jul 24, 2026
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
Critical
CVE-2026-62263
was published
for
org.openidentityplatform.openam:openam-auth-webauthn
(Maven)
Jul 24, 2026
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
High
CVE-2026-59221
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Arena task endpoints can bypass underlying model access controls
Moderate
CVE-2026-59225
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Moderate
CVE-2026-59212
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
High
CVE-2026-59224
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Moderate
CVE-2026-59223
was published
for
open-webui
(pip)
Jul 24, 2026
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
Moderate
CVE-2026-57497
was published
for
github.com/quic-go/webtransport-go
(Go)
Jul 24, 2026
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
High
CVE-2026-55502
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
Moderate
CVE-2026-55499
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Moderate
CVE-2026-55497
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails
Moderate
CVE-2026-55496
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API