GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,796
Maven
5,000+
npm
4,410
NuGet
772
pip
4,181
Pub
12
RubyGems
965
Rust
1,078
Swift
45
Unreviewed advisories
All unreviewed
5,000+
25,266 advisories
Filter by severity
`IterMut` violates Stacked Borrows by invalidating internal pointer
Low
GHSA-rhfx-m35p-ff5j
was published
for
lru
(Rust)
Jan 7, 2026
OpenMetadata's Server-Side Template Injection (SSTI) in FreeMarker email templates leads to RCE
Critical
GHSA-5f29-2333-h9c7
was published
for
org.open-metadata:platform
(Maven)
Jan 7, 2026
CoreShop Vulnerable to SQL Injection via Admin Reports
Moderate
GHSA-ch7p-mpv4-4vg4
was published
for
coreshop/core-shop
(Composer)
Jan 7, 2026
loggingredactor converts non-string types to string types in logs
Low
CVE-2026-22041
was published
for
loggingredactor
(pip)
Jan 7, 2026
Preact has JSON VNode Injection issue
High
CVE-2026-22028
was published
for
preact
(npm)
Jan 7, 2026
n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks
Moderate
CVE-2026-21894
was published
for
n8n
(npm)
Jan 7, 2026
Miniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resources
Moderate
CVE-2026-21885
was published
for
miniflux.app/v2
(Go)
Jan 7, 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
Critical
CVE-2026-21858
was published
for
n8n
(npm)
Jan 7, 2026
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
High
CVE-2026-21441
was published
for
urllib3
(pip)
Jan 7, 2026
pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"
High
CVE-2025-69264
was published
for
pnpm
(npm)
Jan 7, 2026
pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic Dependencies
High
CVE-2025-69263
was published
for
pnpm
(npm)
Jan 7, 2026
pnpm vulnerable to Command Injection via environment variable substitution
High
CVE-2025-69262
was published
for
pnpm
(npm)
Jan 7, 2026
RustFS gRPC GetMetrics deserialization panic enables remote DoS
Moderate
CVE-2025-69255
was published
for
rustfs
(Rust)
Jan 7, 2026
Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write
Moderate
CVE-2025-66560
was published
for
io.quarkus:quarkus-rest
(Maven)
Jan 7, 2026
Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools
High
CVE-2025-9611
was published
for
@playwright/mcp
(npm)
Jan 7, 2026
OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware
Critical
CVE-2026-0650
was published
for
github.com/openflagr/flagr
(Go)
Jan 7, 2026
Directus has open redirect in SAML
Moderate
CVE-2026-22032
was published
for
@directus/api
(npm)
Jan 6, 2026
rsa crate has potential panic on a prime being equal to 1
Low
CVE-2026-21895
was published
for
rsa
(Rust)
Jan 6, 2026
Parsl Monitoring Visualization Vulnerable to SQL Injection
Moderate
CVE-2026-21892
was published
for
parsl
(pip)
Jan 6, 2026
Bypassing Kyverno Policies via Double Policy Exceptions
Critical
GHSA-gg4x-fgg2-h9w9
was published
for
github.com/kyverno/kyverno
(Go)
Jan 6, 2026
Bokeh server applications have Incomplete Origin Validation in WebSockets
Moderate
CVE-2026-21883
was published
for
bokeh
(pip)
Jan 6, 2026
n8n Vulnerable to RCE via Arbitrary File Write
Critical
CVE-2026-21877
was published
for
n8n
(npm)
Jan 6, 2026
Mailpit Proxy Endpoint has Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2026-21859
was published
for
github.com/axllent/mailpit
(Go)
Jan 6, 2026
ProTip!
Advisories are also available from the
GraphQL API