GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
6,246 advisories
Filter by severity
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
Moderate
CVE-2026-59882
was published
for
guzzlehttp/psr7
(Composer)
Jul 21, 2026
Guzzle: URI fragments disclosed in redirect Referer headers
Moderate
GHSA-h95v-h523-3mw8
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Guzzle: Host-only cookie scope is not preserved
Moderate
GHSA-wm3w-8rrp-j577
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Guzzle: Unbounded response cookies risk denial of service
Moderate
GHSA-f283-ghqc-fg79
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
Moderate
CVE-2026-59883
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
Moderate
CVE-2026-59946
was published
for
composer/composer
(Composer)
Jul 20, 2026
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
Moderate
CVE-2026-59947
was published
for
composer/composer
(Composer)
Jul 20, 2026
Guzzle: Proxy-Authorization headers can be sent to origin servers
Moderate
GHSA-94pj-82f3-465w
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Composer: Arbitrary file write outside vendor via malicious transitive package name
High
CVE-2026-59948
was published
for
composer/composer
(Composer)
Jul 20, 2026
Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration
Moderate
GHSA-cvpc-hccg-wmw4
was published
for
verbb/formie
(Composer)
Jul 17, 2026
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
Critical
CVE-2026-55579
was published
for
pheditor/pheditor
(Composer)
Jul 16, 2026
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
High
CVE-2026-55578
was published
for
pheditor/pheditor
(Composer)
Jul 16, 2026
Pheditor has an authenticated terminal command whitelist bypass
High
CVE-2026-54540
was published
for
pheditor/pheditor
(Composer)
Jul 16, 2026
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files
Moderate
GHSA-xg43-5579-qw6v
was published
for
adawolfa/isdoc
(Composer)
Jul 15, 2026
MantisBT: Stored XSS in print_all_bug_page_word.php
High
CVE-2026-62944
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs
Moderate
CVE-2026-52883
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
Moderate
CVE-2026-52882
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: Reflected XSS in admin/install.php via unescaped printf
Critical
CVE-2026-52881
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: Reflected XSS in admin/install.php
Critical
CVE-2026-52847
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Moderate
CVE-2026-54494
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail
Moderate
CVE-2026-50552
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths
High
CVE-2026-54491
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel has SSRF through Authenticated Subsonic podcast feed URLs
Moderate
GHSA-8q6q-m837-fv64
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations
High
CVE-2026-54493
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation
Moderate
CVE-2026-54492
was published
for
phanan/koel
(Composer)
Jul 15, 2026
ProTip!
Advisories are also available from the
GraphQL API