GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
74
GitHub Actions
54
Go
4,080
Maven
5,000+
npm
5,000+
NuGet
994
pip
5,000+
Pub
13
RubyGems
1,095
Rust
1,412
Swift
61
Unreviewed advisories
All unreviewed
5,000+
170 advisories
Filter by severity
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
Moderate
CVE-2026-55766
was published
for
guzzlehttp/psr7
(Composer)
Jun 19, 2026
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
Moderate
CVE-2026-9679
was published
for
undici
(npm)
Jun 19, 2026
Kirby: Request header injection in `Http\Remote`
Moderate
CVE-2026-50188
was published
for
getkirby/cms
(Composer)
Jun 18, 2026
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
High
CVE-2026-55603
was published
for
http-proxy-middleware
(npm)
Jun 18, 2026
Laravel Framework: CRLF injection in default email rule
High
GHSA-5vg9-5847-vvmq
was published
for
laravel/framework
(Composer)
Jun 17, 2026
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
High
GHSA-7cx2-g3h9-382p
was published
for
crawl4ai
(pip)
Jun 16, 2026
aiohttp: CRLF injection in multipart headers
Low
CVE-2026-50269
was published
for
aiohttp
(pip)
Jun 15, 2026
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
Moderate
GHSA-268h-hp4c-crq3
was published
for
nodemailer
(npm)
Jun 15, 2026
form-data: CRLF injection in form-data via unescaped multipart field names and filenames
High
CVE-2026-12143
was published
for
form-data
(npm)
Jun 15, 2026
SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator
Moderate
CVE-2026-28970
was published
for
github.com/apple/swift-nio
(Swift)
Jun 12, 2026
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server...
High
Unreviewed
CVE-2026-50629
was published
Jun 12, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
Moderate
CVE-2026-49214
was published
for
guzzlehttp/psr7
(Composer)
Jun 11, 2026
Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric...
Moderate
Unreviewed
CVE-2026-50639
was published
Jun 10, 2026
Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric...
High
Unreviewed
CVE-2026-50637
was published
Jun 10, 2026
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric...
Critical
Unreviewed
CVE-2026-50638
was published
Jun 10, 2026
Net::IMAP: Command Injection via ID command argument
Moderate
CVE-2026-47242
was published
for
net-imap
(RubyGems)
Jun 9, 2026
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
Moderate
CVE-2026-47240
was published
for
net-imap
(RubyGems)
Jun 9, 2026
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections.
DataDog::DogStatsd...
Critical
Unreviewed
CVE-2026-9270
was published
Jun 5, 2026
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags.
...
Critical
Unreviewed
CVE-2026-11362
was published
Jun 5, 2026
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output...
High
Unreviewed
CVE-2026-50292
was published
Jun 4, 2026
Etsy::StatsD versions through 1.002002 for Perl allow metric injections.
The metric names and...
High
Unreviewed
CVE-2026-46741
was published
Jun 4, 2026
Net::Statsd versions before 0.13 for Perl allow metric injections.
The metric names are not...
Moderate
Unreviewed
CVE-2026-46739
was published
Jun 4, 2026
Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections.
The metric...
Moderate
Unreviewed
CVE-2026-8722
was published
Jun 4, 2026
Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the...
Moderate
Unreviewed
CVE-2026-49130
was published
May 28, 2026
Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names
Moderate
CVE-2026-45070
was published
for
symfony/mime
(Composer)
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API