GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
123,590 advisories
Filter by severity
Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server...
High
Unreviewed
CVE-2026-42255
was published
Apr 26, 2026
A vulnerability was identified in Tenda F456 1.0.0.5. The impacted element is the function...
High
Unreviewed
CVE-2026-7019
was published
Apr 26, 2026
GitPython has Command Injection via Git options bypass
High
GHSA-rpm5-65cw-6hj4
was published
for
GitPython
(pip)
Apr 25, 2026
GitPython: Unsafe option check validates multi_options before shlex.split transformation
High
GHSA-x2qx-6953-8485
was published
for
GitPython
(pip)
Apr 25, 2026
Cillium exposes sensitive information included in the cilium-bugtool debug archive
High
CVE-2026-41520
was published
for
github.com/cilium/cilium
(Go)
Apr 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write
High
GHSA-74m3-9qvm-rp9h
was published
for
github.com/openziti/zrok
(Go)
Apr 25, 2026
Heimdall has an authorization bypass via path normalization mismatch
High
GHSA-3q34-rx83-r6mq
was published
for
github.com/dadrus/heimdall
(Go)
Apr 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass
High
GHSA-72h4-mxfc-jx37
was published
for
github.com/dadrus/heimdall
(Go)
Apr 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation
High
GHSA-43jv-5j4x-qv67
was published
for
github.com/dadrus/heimdall
(Go)
Apr 25, 2026
LiteLLM: Authenticated command execution via MCP stdio test endpoints
High
GHSA-v4p8-mg3p-g94g
was published
for
litellm
(pip)
Apr 25, 2026
A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function...
High
Unreviewed
CVE-2026-6992
was published
Apr 25, 2026
A flaw has been found in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon. This issue affects the...
High
Unreviewed
CVE-2026-6988
was published
Apr 25, 2026
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp...
High
Unreviewed
CVE-2026-42171
was published
Apr 25, 2026
CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI...
High
Unreviewed
CVE-2026-41473
was published
Apr 24, 2026
Kyverno Controller Denial of Service via forEach Mutation Panic
High
CVE-2026-41485
was published
for
github.com/kyverno/kyverno
(Go)
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
CVE-2026-41325
was published
for
getkirby/cms
(Composer)
Apr 24, 2026
TYPO3 CMS Stores Cleartext Password in User Settings Module
High
CVE-2026-6553
was published
for
typo3/cms-backend
(Composer)
Apr 24, 2026
Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
High
CVE-2026-40912
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
k8sGPT has Prompt Injection through its k8sGPT-Operator
High
GHSA-rp7v-4384-hfrp
was published
for
github.com/k8sgpt-ai/k8sgpt
(Go)
Apr 24, 2026
Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
High
CVE-2026-40068
was published
for
@anthropic-ai/claude-code
(npm)
Apr 24, 2026
Traefik: Pre-authentication decision bypass due to forwarded alias spoofing
High
CVE-2026-39858
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authentication
High
CVE-2026-35051
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
Zserio Runtime: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization
High
CVE-2026-33524
was published
for
io.github.ndsev:zserio-runtime
(Maven)
Apr 24, 2026
rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
High
GHSA-82j2-j2ch-gfr8
was published
for
rustls-webpki
(Rust)
Apr 24, 2026
Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover
High
GHSA-4f9j-vr4p-642r
was published
for
@budibase/backend-core
(npm)
Apr 24, 2026
ProTip!
Advisories are also available from the
GraphQL API