GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,494
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,272 advisories
Filter by severity
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types
High
CVE-2026-44795
was published
for
io.spinnaker.orca:orca-core
(Maven)
Jun 22, 2026
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
High
CVE-2026-48006
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 11, 2026
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
High
CVE-2026-48059
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jun 11, 2026
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
High
CVE-2025-66024
was published
for
org.xwiki.contrib.blog:application-blog-ui
(Maven)
Mar 4, 2026
CometVisu Backend for openHAB affected by SSRF/XSS
High
CVE-2024-42467
was published
for
org.openhab.ui.bundles:org.openhab.ui.cometvisu
(Maven)
Aug 9, 2024
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
High
CVE-2026-45799
was published
for
com.squareup.wire:wire-runtime
(Maven)
May 19, 2026
json-smart Uncontrolled Recursion vulnerability
High
CVE-2023-1370
was published
for
net.minidev:json-smart
(Maven)
Mar 23, 2023
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
High
CVE-2026-48748
was published
for
io.netty:netty-codec-http3
(Maven)
Jun 15, 2026
Netty has Insufficient Bailiwick Validation for NS Records
High
CVE-2026-47691
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
High
CVE-2026-45674
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
High
GHSA-r7wm-3cxj-wff9
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Jul 21, 2026
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
High
CVE-2026-56819
was published
for
io.netty:netty-codec-http2
(Maven)
Jul 31, 2026
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
High
CVE-2026-41695
was published
for
org.springframework.data:spring-data-commons
(Maven)
Jul 31, 2026
Spring Framework Algorithmic Denial of Service via SpEL Expressions
High
CVE-2026-41850
was published
for
org.springframework:spring-expression
(Maven)
Jun 9, 2026
Spring Framework Cross-site Scripting via JavaScriptUtils
High
CVE-2026-41845
was published
for
org.springframework:spring-webmvc
(Maven)
Jun 9, 2026
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
High
CVE-2026-41849
was published
for
org.springframework:spring-expression
(Maven)
Jun 9, 2026
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
High
CVE-2026-41842
was published
for
org.springframework:spring-webflux
(Maven)
Jun 9, 2026
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
High
CVE-2026-54513
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
High
CVE-2026-50559
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
Jul 29, 2026
Spring LDAP has Authentication Bypass with Empty Password
High
CVE-2026-41720
was published
for
org.springframework.ldap:spring-ldap-core
(Maven)
Jun 9, 2026
Spring HATEOAS heap exhaustion through unbounded internal caching
High
CVE-2026-41007
was published
for
org.springframework.hateoas:spring-hateoas
(Maven)
Jun 9, 2026
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
High
CVE-2026-41006
was published
for
org.springframework.hateoas:spring-hateoas
(Maven)
Jun 9, 2026
veraPDF Validation XXE via Rich Text
High
CVE-2026-54078
was published
for
org.verapdf:validation-model
(Maven)
Jul 29, 2026
veraPDF Validation XXE via XFA
High
CVE-2026-54079
was published
for
org.verapdf:validation-model
(Maven)
Jul 29, 2026
Quarkus has Authentication/Authorization bypasses
High
CVE-2026-39852
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
May 4, 2026
ProTip!
Advisories are also available from the
GraphQL API