GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
164,411 advisories
Filter by severity
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Moderate
GHSA-cj75-f6xr-r4g7
was published
for
rails-html-sanitizer
(RubyGems)
Jul 21, 2026
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
Moderate
GHSA-9mqv-5hh9-4cgg
was published
for
@hono/node-server
(npm)
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
Moderate
GHSA-9wjq-cp2p-hrgf
was published
for
loofah
(RubyGems)
Jul 21, 2026
jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization
Moderate
CVE-2026-59889
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jul 21, 2026
TypeORM: migration:generate template-literal code injection
Moderate
GHSA-2rp8-mm9q-fp49
was published
for
typeorm
(npm)
Jul 21, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Moderate
CVE-2026-58429
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Moderate
CVE-2026-59765
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Moderate
CVE-2026-57897
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
Moderate
CVE-2026-58510
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Public-only API token restriction is not enforced on team API routes
Moderate
CVE-2026-58431
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
Moderate
CVE-2026-58427
was published
for
gitea.dev
(Go)
Jul 21, 2026
Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum...
Moderate
Unreviewed
CVE-2026-65058
was published
Jul 21, 2026
Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers...
Moderate
Unreviewed
CVE-2026-65055
was published
Jul 21, 2026
djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in...
Moderate
Unreviewed
CVE-2026-64822
was published
Jul 21, 2026
djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that...
Moderate
Unreviewed
CVE-2026-64821
was published
Jul 21, 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via...
Moderate
Unreviewed
CVE-2026-63136
was published
Jul 21, 2026
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-63139
was published
Jul 21, 2026
Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data...
Moderate
Unreviewed
CVE-2026-63140
was published
Jul 21, 2026
kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure...
Moderate
Unreviewed
CVE-2026-63092
was published
Jul 21, 2026
Tanium addressed an information disclosure vulnerability in Connect.
Moderate
Unreviewed
CVE-2026-12139
was published
Jul 21, 2026
Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity...
Moderate
Unreviewed
CVE-2026-56146
was published
Jul 21, 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via...
Moderate
Unreviewed
CVE-2026-56145
was published
Jul 21, 2026
Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited...
Moderate
Unreviewed
CVE-2026-56144
was published
Jul 21, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of...
Moderate
Unreviewed
CVE-2026-42397
was published
Jul 21, 2026
A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an...
Moderate
Unreviewed
CVE-2026-12548
was published
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API