GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
118
GitHub Actions
56
Go
4,844
Maven
5,000+
npm
5,000+
NuGet
1,129
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
7,118 advisories
Filter by severity
http4s-scala-xml has an XML External Entity (XXE) processing issue
Critical
CVE-2026-61741
was published
for
org.http4s:http4s-scala-xml_2.12
(Maven)
Sep 24, 2026
Jawn: Quadratic parsing effort in AsyncParser
High
CVE-2026-61814
was published
for
org.typelevel:jawn-parser_2.12
(Maven)
Sep 23, 2026
Jawn: Uncontrolled nesting depth in JSON parser
High
CVE-2026-59990
was published
for
org.typelevel:jawn-parser_2.12
(Maven)
Sep 23, 2026
JLine: ReDoS in Nano Editor Regex Search Mode
Moderate
CVE-2026-77421
was published
for
org.jline:jline-builtins
(Maven)
Sep 23, 2026
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping
High
CVE-2026-77422
was published
for
org.jline:jline-builtins
(Maven)
Sep 23, 2026
JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable
Moderate
CVE-2026-77420
was published
for
org.jline:jline-reader
(Maven)
Sep 23, 2026
Moquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug
Critical
CVE-2026-85724
was published
for
io.moquette:moquette-broker
(Maven)
Sep 23, 2026
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
Moderate
CVE-2026-69190
was published
for
org.graylog2:graylog2-server
(Maven)
Sep 22, 2026
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
Moderate
CVE-2026-65829
was published
for
MPXJ.Net
(RubyGems)
Sep 22, 2026
MPXJ: XXE Vulnerability in MerlinReader
High
CVE-2026-61570
was published
for
MPXJ.Net
(RubyGems)
Sep 22, 2026
io.moquette:moquette-broker has a Missing Authorization issue
High
CVE-2026-85058
was published
for
io.moquette:moquette-broker
(Maven)
Sep 18, 2026
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
Critical
CVE-2025-53837
was published
for
org.xwiki.rendering:xwiki-rendering-xml
(Maven)
Sep 18, 2026
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text
High
CVE-2026-77615
was published
for
org.opencastproject:opencast-engage-paella-player-7
(Maven)
Sep 18, 2026
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
High
CVE-2026-81876
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.r5
(Maven)
Sep 17, 2026
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
High
CVE-2026-81875
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.r5
(Maven)
Sep 17, 2026
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target
Moderate
CVE-2026-85717
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
Moderate
CVE-2026-85720
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
High
CVE-2026-85721
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses
Low
CVE-2026-85716
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
Moderate
CVE-2026-73245
was published
for
io.kestra:kestra
(Maven)
Sep 17, 2026
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
High
CVE-2026-73247
was published
for
io.kestra:core
(Maven)
Sep 17, 2026
Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root
Low
CVE-2026-86071
was published
for
com.github.junrar:junrar
(Maven)
Sep 17, 2026
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
Low
CVE-2026-61700
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Sep 17, 2026
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)
High
CVE-2026-63126
was published
for
com.squareup.wire:wire-runtime
(Maven)
Sep 17, 2026
RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement
High
CVE-2026-75516
was published
for
com.rabbitmq:amqp-client
(Maven)
Sep 17, 2026
ProTip!
Advisories are also available from the
GraphQL API