GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,630
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,850
Pub
13
RubyGems
1,045
Rust
1,301
Swift
53
Unreviewed advisories
All unreviewed
5,000+
29,573 advisories
Filter by severity
ps_checkout allows unauthorized method invocation through unvalidated parameter
Low
GHSA-mqq7-wxx5-mp8h
was published
for
prestashop/ps_checkout
(Composer)
Apr 30, 2026
Contras Affected by CopyFile Policy Subversion via Symlinks
High
GHSA-rh99-wc69-c255
was published
for
github.com/edgelesssys/contrast
(Go)
Apr 30, 2026
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets)
High
CVE-2026-42461
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
Apr 30, 2026
auth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonation
Critical
CVE-2026-42560
was published
for
github.com/go-pkgz/auth
(Go)
Apr 30, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
Critical
CVE-2026-42354
was published
for
sentry
(pip)
Apr 30, 2026
OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
Moderate
CVE-2026-42191
was published
for
OpenTelemetry.Exporter.OpenTelemetryProtocol
(NuGet)
Apr 30, 2026
ydb-go-sdk's transactions are not committed using the `options.WithCommit()` option on last call `table.Transaction.Execute` in transaction
Low
GHSA-28xx-pppm-vqff
was published
for
github.com/ydb-platform/ydb-go-sdk/v3
(Go)
Apr 30, 2026
Clerk has an authorization bypass when combining organization, billing, or reverification checks
High
CVE-2026-42349
was published
for
@clerk/astro
(npm)
Apr 30, 2026
n8n-mcp's IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders
High
CVE-2026-42449
was published
for
n8n-mcp
(npm)
Apr 30, 2026
Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation
High
GHSA-83hf-93m4-rgwq
was published
for
hickory-recursor
(Rust)
Apr 30, 2026
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
Moderate
CVE-2026-42032
was published
for
ckan
(pip)
Apr 30, 2026
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
Moderate
CVE-2026-41654
was published
for
weblate
(pip)
Apr 30, 2026
Weblate Doesn't Invalidate API Token on Password Change
Moderate
CVE-2026-41519
was published
for
weblate
(pip)
Apr 30, 2026
Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix)
Critical
CVE-2026-40281
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 30, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
High
CVE-2026-40171
was published
for
@jupyter-notebook/help-extension
(npm)
Apr 30, 2026
Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL
High
CVE-2026-39383
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 30, 2026
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
Critical
CVE-2026-40280
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 30, 2026
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
High
CVE-2026-42031
was published
for
ckan
(pip)
Apr 29, 2026
Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool
Moderate
CVE-2026-41686
was published
for
@anthropic-ai/sdk
(npm)
Apr 29, 2026
i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters
High
CVE-2026-42353
was published
for
i18next-http-middleware
(npm)
Apr 29, 2026
netfoil's optional seccomp sandboxing was not applied
Moderate
GHSA-vjgj-42f6-7997
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Apr 29, 2026
Netfoil has incorrect allowlist enforcement
Moderate
GHSA-84g5-x8j3-7235
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Apr 29, 2026
pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
High
CVE-2026-42352
was published
for
pygeoapi
(pip)
Apr 29, 2026
pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
High
CVE-2026-42351
was published
for
pygeoapi
(pip)
Apr 29, 2026
Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer
High
CVE-2026-41680
was published
for
marked
(npm)
Apr 29, 2026
ProTip!
Advisories are also available from the
GraphQL API