GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
33,569 advisories
Filter by severity
fast-uri vulnerable to host confusion via literal backslash authority delimiter
High
CVE-2026-16221
was published
for
fast-uri
(npm)
Jul 21, 2026
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
High
GHSA-f88m-g3jw-g9cj
was published
for
sharp
(npm)
Jul 21, 2026
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
High
GHSA-8r6m-32jq-jx6q
was published
for
fast-xml-parser
(npm)
Jul 21, 2026
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
High
GHSA-rwj8-pgh3-r573
was published
for
gitpython
(pip)
Jul 21, 2026
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Moderate
GHSA-cj75-f6xr-r4g7
was published
for
rails-html-sanitizer
(RubyGems)
Jul 21, 2026
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
Moderate
GHSA-9mqv-5hh9-4cgg
was published
for
@hono/node-server
(npm)
Jul 21, 2026
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
High
GHSA-hrxh-6v49-42gf
was published
for
google.golang.org/grpc
(Go)
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Low
GHSA-5qhf-9phg-95m2
was published
for
loofah
(RubyGems)
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
Moderate
GHSA-9wjq-cp2p-hrgf
was published
for
loofah
(RubyGems)
Jul 21, 2026
jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization
Moderate
CVE-2026-59889
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jul 21, 2026
TypeORM: migration:generate template-literal code injection
Moderate
GHSA-2rp8-mm9q-fp49
was published
for
typeorm
(npm)
Jul 21, 2026
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
High
GHSA-r7wm-3cxj-wff9
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Jul 21, 2026
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
High
CVE-2026-20779
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Moderate
CVE-2026-58429
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Moderate
CVE-2026-59765
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API
Low
CVE-2026-58511
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Moderate
CVE-2026-57897
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
Moderate
CVE-2026-58510
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Public-only API token restriction is not enforced on team API routes
Moderate
CVE-2026-58431
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
Moderate
CVE-2026-58427
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
High
CVE-2026-58422
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Notification API leaks private issue metadata after access revocation
High
CVE-2026-58419
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unauthorized Access to Labels of Private Organizations
High
CVE-2026-25038
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write
High
CVE-2026-27775
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
High
CVE-2026-24451
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API