GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
118
GitHub Actions
56
Go
4,844
Maven
5,000+
npm
5,000+
NuGet
1,129
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
3,385 advisories
Filter by severity
http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`
Moderate
GHSA-jrpc-7vxp-69p6
was published
for
org.http4k:http4k-core
(Maven)
Jun 19, 2026
JLine: ReDoS in Nano Editor Regex Search Mode
Moderate
CVE-2026-77421
was published
for
org.jline:jline-builtins
(Maven)
Sep 23, 2026
JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable
Moderate
CVE-2026-77420
was published
for
org.jline:jline-reader
(Maven)
Sep 23, 2026
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
Moderate
CVE-2026-69190
was published
for
org.graylog2:graylog2-server
(Maven)
Sep 22, 2026
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
Moderate
CVE-2026-65829
was published
for
MPXJ.Net
(RubyGems)
Sep 22, 2026
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
Moderate
CVE-2026-48043
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 11, 2026
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target
Moderate
CVE-2026-85717
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
Moderate
CVE-2026-85720
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
Moderate
CVE-2026-73245
was published
for
io.kestra:kestra
(Maven)
Sep 17, 2026
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators
Moderate
CVE-2026-69201
was published
for
org.http4s:http4s-server_2.12
(Maven)
Sep 15, 2026
Http4s: Ember chunk parser lenience (TE.TE request smuggling)
Moderate
CVE-2026-69216
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin
Moderate
CVE-2026-69215
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
Moderate
CVE-2026-69214
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Http4s: DigestAuth allows replay of captured requests
Moderate
CVE-2026-69206
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
Moderate
CVE-2026-44913
was published
for
org.apache.nifi:nifi-cdc-mysql-processors
(Maven)
Jun 22, 2026
Apache NiFi fails to validate proxy host headers when constructing qualified URLs
Moderate
CVE-2026-54665
was published
for
org.apache.nifi:nifi-jetty
(Maven)
Jun 22, 2026
Apache Atlas UI: Authenticated User XSS
Moderate
CVE-2025-62198
was published
for
org.apache.atlas:atlas-dashboardv2
(Maven)
Jun 22, 2026
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion
Moderate
CVE-2026-11748
was published
for
com.linecorp.centraldogma:centraldogma-server-auth-shiro
(Maven)
Sep 11, 2026
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
Moderate
CVE-2026-75596
was published
for
io.netty:netty-handler
(Maven)
Sep 8, 2026
axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-248h-974q-xrc2
was published
for
com.getaxonflow:axonflow-sdk
(Maven)
May 6, 2026
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
Moderate
CVE-2026-18401
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Feb 28, 2026
Duplicate Advisory: jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
Moderate
GHSA-6qm2-mcq7-53qp
was published
for
tools.jackson.core:jackson-core
(Maven)
Aug 4, 2026
•
withdrawn
Apache Tomcat - Client certificate verification bypass
Moderate
CVE-2025-66614
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Feb 17, 2026
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
Moderate
CVE-2026-55860
was published
for
org.mariadb:r2dbc-mariadb
(Maven)
Aug 28, 2026
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
Moderate
CVE-2026-55859
was published
for
org.mariadb:r2dbc-mariadb
(Maven)
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API