GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,385
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,124
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
132,098 advisories
Filter by severity
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
High
CVE-2026-54481
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
High
CVE-2026-58424
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
High
CVE-2026-58423
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
High
CVE-2026-58421
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
High
CVE-2026-28740
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API
High
CVE-2026-56654
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
High
CVE-2026-56755
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
High
CVE-2026-58439
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
High
GHSA-956x-8gvw-wg5v
was published
for
GitPython
(pip)
Jul 21, 2026
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
High
GHSA-2f96-g7mh-g2hx
was published
for
GitPython
(pip)
Jul 21, 2026
GitPython unsafe clone option gate bypass through joined short options
High
GHSA-v396-v7q4-x2qj
was published
for
GitPython
(pip)
Jul 21, 2026
SVGO removeScripts plugin leaves some executable scripts intact
High
GHSA-2p49-hgcm-8545
was published
for
svgo
(npm)
Jul 21, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
High
CVE-2026-57894
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
pyasn1: Uncontrolled resource consumption when converting decoded REAL values
High
CVE-2026-59886
was published
for
pyasn1
(pip)
Jul 21, 2026
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
High
CVE-2026-59885
was published
for
pyasn1
(pip)
Jul 21, 2026
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
High
CVE-2026-59884
was published
for
pyssn1
(pip)
Jul 21, 2026
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
High
CVE-2026-59892
was published
for
@opentelemetry/propagator-jaeger
(npm)
Jul 21, 2026
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
High
CVE-2026-59887
was published
for
linkify-it
(npm)
Jul 21, 2026
aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
High
CVE-2026-13760
was published
for
aws-cdk-lib
(npm)
Jul 21, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization
High
CVE-2026-13676
was published
for
fast-uri
(npm)
Jul 21, 2026
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
High
CVE-2026-59879
was published
for
immutable
(npm)
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
CVE-2026-61666
was published
for
websocket-driver
(RubyGems)
Jul 21, 2026
This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0...
High
Unreviewed
CVE-2026-21579
was published
Jul 21, 2026
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of...
High
Unreviewed
CVE-2026-21575
was published
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API