GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,585
Maven
5,000+
npm
5,000+
NuGet
923
pip
4,817
Pub
13
RubyGems
1,043
Rust
1,251
Swift
53
Unreviewed advisories
All unreviewed
5,000+
29,353 advisories
Filter by severity
melange has Path Traversal via .PKGINFO in --persist-lint-results
Moderate
CVE-2026-29051
was published
for
chainguard.dev/melange
(Go)
Apr 23, 2026
melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses
Moderate
CVE-2026-29050
was published
for
chainguard.dev/melange
(Go)
Apr 23, 2026
Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)
Low
CVE-2026-41321
was published
for
@astrojs/cloudflare
(npm)
Apr 23, 2026
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
High
CVE-2026-41900
was published
for
openlearnx
(npm)
Apr 23, 2026
OpenTelemetry.Sampler.AWS & OpenTelemetry.Resources.AWS have unbounded HTTP response body reads
Moderate
CVE-2026-41173
was published
for
OpenTelemetry.Resources.AWS
(NuGet)
Apr 23, 2026
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
Moderate
CVE-2026-40894
was published
for
OpenTelemetry.Api
(NuGet)
Apr 23, 2026
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
Moderate
CVE-2026-40891
was published
for
OpenTelemetry.Exporter.OpenTelemetryProtocol
(NuGet)
Apr 23, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
High
CVE-2026-40886
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Apr 23, 2026
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
Moderate
CVE-2026-40182
was published
for
OpenTelemetry.Exporter.OpenTelemetryProtocol
(NuGet)
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Moderate
CVE-2026-40099
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
Apktool: Path Traversal to Arbitrary File Write
High
CVE-2026-39973
was published
for
org.apktool:apktool-lib
(Maven)
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
CVE-2026-34587
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
High
CVE-2026-33318
was published
for
@actual-app/sync-server
(npm)
Apr 23, 2026
go-ntlmssp NTLM challenges can panic on malformed payloads
Moderate
CVE-2026-32952
was published
for
github.com/Azure/go-ntlmssp
(Go)
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Moderate
CVE-2026-32870
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
Critical
CVE-2025-62373
was published
for
pipecat-ai
(pip)
Apr 23, 2026
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
High
CVE-2026-40372
was published
for
Microsoft.AspNetCore.DataProtection
(NuGet)
Apr 23, 2026
Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed
Moderate
CVE-2026-41322
was published
for
@astrojs/node
(npm)
Apr 23, 2026
n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests
Moderate
CVE-2026-41495
was published
for
n8n-mcp
(npm)
Apr 23, 2026
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS
Moderate
GHSA-rhf7-wvw3-vjvm
was published
for
github.com/patrickhener/goshs
(Go)
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
Critical
GHSA-2wvh-87g2-89hr
was published
for
openc3
(RubyGems)
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
Critical
GHSA-v529-vhwc-wfc5
was published
for
openc3
(RubyGems)
Apr 23, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
Moderate
GHSA-ffq5-qpvf-xq7x
was published
for
openc3
(RubyGems)
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
Moderate
GHSA-4jvx-93h3-f45h
was published
for
openc3
(RubyGems)
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
High
GHSA-wgx6-g857-jjf7
was published
for
openc3
(RubyGems)
Apr 22, 2026
ProTip!
Advisories are also available from the
GraphQL API