GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
145 advisories
Filter by severity
Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names
Moderate
CVE-2026-45070
was published
for
symfony/mime
(Composer)
May 27, 2026
Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
High
CVE-2026-45067
was published
for
symfony/mime
(Composer)
May 27, 2026
Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections.
The metric...
Unknown
Unreviewed
CVE-2026-46740
was published
May 27, 2026
Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections.
The values from...
High
Unreviewed
CVE-2026-8788
was published
May 18, 2026
Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections.
The metric names and...
High
Unreviewed
CVE-2026-46720
was published
May 17, 2026
Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections.
The metric names...
Moderate
Unreviewed
CVE-2026-46719
was published
May 16, 2026
Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint...
High
Unreviewed
CVE-2026-32993
was published
May 14, 2026
PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when...
Moderate
Unreviewed
CVE-2026-35504
was published
May 12, 2026
cowlib: Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
Low
CVE-2026-43969
was published
for
cowlib
(Erlang)
May 11, 2026
ninenines cowlib: Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability allows SSE event splitting and injection via unvalidated field values
Moderate
CVE-2026-43968
was published
for
cowlib
(Erlang)
May 11, 2026
eventsource-encoder vulnerable to SSE event injection via unsanitized `event` and `id` fields
Moderate
CVE-2026-44214
was published
for
eventsource-encoder
(npm)
May 8, 2026
Netty Redis Codec Encoder has a CRLF Injection Issue
Moderate
CVE-2026-42586
was published
for
io.netty:netty-codec-redis
(Maven)
May 7, 2026
sse-channel: SSE Injection via unsanitized event fields
Moderate
CVE-2026-44217
was published
for
sse-channel
(npm)
May 5, 2026
AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing
Moderate
CVE-2026-43882
was published
for
wwbn/avideo
(Composer)
May 5, 2026
Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injection
Moderate
CVE-2026-41417
was published
for
io.netty:netty-codec-http
(Maven)
May 5, 2026
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
Moderate
CVE-2026-42037
was published
for
axios
(npm)
May 5, 2026
net-imap vulnerable to command Injection via "raw" arguments to multiple commands
Moderate
CVE-2026-42257
was published
for
net-imap
(RubyGems)
May 4, 2026
net-imap vulnerable to command Injection via unvalidated Symbol inputs
Moderate
CVE-2026-42258
was published
for
net-imap
(RubyGems)
May 4, 2026
Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM...
High
Unreviewed
CVE-2026-5140
was published
Apr 29, 2026
PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes
High
GHSA-mh6w-vxff-9wqp
was published
for
phpunit/phpunit
(Composer)
Apr 22, 2026
The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and...
Moderate
Unreviewed
CVE-2026-2717
was published
Apr 22, 2026
SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of...
Moderate
Unreviewed
CVE-2026-32964
was published
Apr 20, 2026
PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes
High
CVE-2026-41570
was published
for
phpunit/phpunit
(Composer)
Apr 18, 2026
MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing...
High
Unreviewed
CVE-2026-6351
was published
Apr 16, 2026
Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()
High
CVE-2026-41230
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
ProTip!
Advisories are also available from the
GraphQL API