GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
13,623 advisories
Filter by severity
SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs
Moderate
CVE-2026-40091
was published
for
github.com/authzed/spicedb
(Go)
Apr 14, 2026
GPT-Pilot contains a command injection vulnerability in the Executor.run() method
Moderate
CVE-2026-31246
was published
for
gpt-pilot
(pip)
May 11, 2026
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
Moderate
CVE-2026-31245
was published
for
mem0ai
(pip)
May 12, 2026
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
Moderate
CVE-2026-31241
was published
for
mem0ai
(pip)
May 12, 2026
Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export
Moderate
CVE-2026-45703
was published
for
pimcore/pimcore
(Composer)
May 27, 2026
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
Moderate
CVE-2026-45309
was published
for
asyncssh
(pip)
May 27, 2026
Synfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]
Moderate
CVE-2026-45075
was published
for
symfony/http-kernel
(Composer)
May 27, 2026
Symfony's Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
Moderate
CVE-2026-45074
was published
for
symfony/security-http
(Composer)
May 27, 2026
Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix
Moderate
CVE-2026-45073
was published
for
symfony/cache
(Composer)
May 27, 2026
Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names
Moderate
CVE-2026-45070
was published
for
symfony/mime
(Composer)
May 27, 2026
Symfony's OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims
Moderate
CVE-2026-45069
was published
for
symfony/security-http
(Composer)
May 27, 2026
Symfony has an Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address
Moderate
CVE-2026-45068
was published
for
symfony/mailer
(Composer)
May 27, 2026
Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification
Moderate
CVE-2026-45066
was published
for
symfony/html-sanitizer
(Composer)
May 27, 2026
Symfony's HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
Moderate
CVE-2026-45064
was published
for
symfony/html-sanitizer
(Composer)
May 27, 2026
CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression
Moderate
CVE-2026-44981
was published
for
github.com/crowdsecurity/crowdsec
(Go)
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Moderate
CVE-2026-45334
was published
for
getkirby/cms
(Composer)
May 27, 2026
Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
Moderate
CVE-2026-45065
was published
for
symfony/routing
(Composer)
May 27, 2026
Lemmy has SSRF in /api/v3/post via Webmention dispatch
Moderate
CVE-2026-42180
was published
for
lemmy_api_common
(Rust)
Apr 24, 2026
ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
Moderate
CVE-2026-46693
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 22, 2026
@hapi/wreck leaks sensitive `Proxy-Authorization` header across cross-hostname redirects
Moderate
CVE-2026-44979
was published
for
@hapi/wreck
(npm)
May 27, 2026
LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`
Moderate
CVE-2026-44646
was published
for
liquidjs
(npm)
May 27, 2026
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
Moderate
CVE-2026-44645
was published
for
liquidjs
(npm)
May 27, 2026
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
Moderate
CVE-2026-44644
was published
for
liquidjs
(npm)
May 27, 2026
Yamcs has No Rate Limiting on Authentication Endpoint
Moderate
CVE-2026-44596
was published
for
org.yamcs:yamcs-core
(Maven)
May 27, 2026
Yamcs vulnerable to unauthorized user enumeration via IAM API endpoints
Moderate
CVE-2026-44595
was published
for
org.yamcs:yamcs-core
(Maven)
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API