GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
12 advisories
Filter by severity
Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names
Moderate
CVE-2026-45070
was published
for
symfony/mime
(Composer)
May 27, 2026
Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
High
CVE-2026-45067
was published
for
symfony/mime
(Composer)
May 27, 2026
AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing
Moderate
CVE-2026-43882
was published
for
wwbn/avideo
(Composer)
May 5, 2026
PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes
High
GHSA-mh6w-vxff-9wqp
was published
for
phpunit/phpunit
(Composer)
Apr 22, 2026
PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes
High
CVE-2026-41570
was published
for
phpunit/phpunit
(Composer)
Apr 18, 2026
Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()
High
CVE-2026-41230
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
High
CVE-2026-39394
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
Moodle CRLF Injection Vulnerability in Calendar Component
Moderate
CVE-2011-4203
was published
for
moodle/moodle
(Composer)
May 13, 2022
Joomla! vulnerable to CRLF injection
Moderate
CVE-2007-4190
was published
for
joomla/application
(Composer)
May 1, 2022
CRLF Injection in microweber
High
CVE-2022-0666
was published
for
microweber/microweber
(Composer)
Feb 19, 2022
phpservermon is vulnerable to CRLF Injection
Moderate
CVE-2021-4097
was published
for
phpservermon/phpservermon
(Composer)
Dec 16, 2021
Cachet vulnerable to new line injection during configuration edition
High
CVE-2021-39172
was published
for
cachethq/cachet
(Composer)
Aug 30, 2021
ProTip!
Advisories are also available from the
GraphQL API