GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,049
Maven
5,000+
npm
4,787
NuGet
825
pip
4,384
Pub
12
RubyGems
988
Rust
1,144
Swift
50
Unreviewed advisories
All unreviewed
5,000+
26,464 advisories
Filter by severity
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
High
GHSA-5c6j-r48x-rmvq
was published
for
serialize-javascript
(npm)
Feb 28, 2026
malcontent: Nested archive extraction failure can drop content from scan inputs
Moderate
CVE-2026-28407
was published
for
github.com/chainguard-dev/malcontent
(Go)
Feb 28, 2026
PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages
Moderate
CVE-2026-28338
was published
for
net.sourceforge.pmd:pmd-core
(Maven)
Feb 28, 2026
Hive has Double-free and Use After Free Vulnerabilities
Moderate
GHSA-j8cj-hw74-64jv
was published
for
hivex
(Rust)
Feb 28, 2026
@fastify/middie has Improper Path Normalization when Using Path-Scoped Middleware
High
CVE-2026-2880
was published
for
@fastify/middie
(npm)
Feb 28, 2026
pypdf: Manipulated RunLengthDecode streams can exhaust RAM
Moderate
CVE-2026-28351
was published
for
pypdf
(pip)
Feb 28, 2026
osctrl has Stored Cross-Site Scripting (XSS) in On-Demand Query List
Moderate
CVE-2026-28280
was published
for
github.com/jmpsec/osctrl
(Go)
Feb 28, 2026
osctrl is Vulnerable to OS Command Injection via Environment Configuration
High
CVE-2026-28279
was published
for
github.com/jmpsec/osctrl
(Go)
Feb 28, 2026
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
Low
GHSA-fpg4-jhqr-589c
was published
for
@sveltejs/kit
(npm)
Feb 28, 2026
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
High
GHSA-72hv-8253-57qq
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Feb 28, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse
Critical
CVE-2026-28268
was published
for
code.vikunja.io/api
(Go)
Feb 28, 2026
Junrar has an arbitrary file write due to backslash Path Traversal bypass in LocalFolderExtractor on Linux/Unix
Moderate
CVE-2026-28208
was published
for
com.github.junrar:junrar
(Maven)
Feb 27, 2026
OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata
Moderate
GHSA-7jx5-9fjg-hp4m
was published
for
openclaw
(npm)
Feb 27, 2026
OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth)
Moderate
GHSA-82g8-464f-2mv7
was published
for
openclaw
(npm)
Feb 27, 2026
Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass
High
CVE-2026-27939
was published
for
statamic/cms
(Composer)
Feb 27, 2026
ZITADEL has potential SSRF via Actions
Low
CVE-2026-27945
was published
for
github.com/zitadel/zitadel/v2
(Go)
Feb 27, 2026
ZITADEL Users Can Self-Verify Email/Phone via UpdateHumanUser API
High
CVE-2026-27946
was published
for
github.com/zitadel/zitadel
(Go)
Feb 27, 2026
ZITADEL's truncated opaque tokens are still valid
Moderate
CVE-2026-27840
was published
for
github.com/zitadel/zitadel
(Go)
Feb 27, 2026
phpMyFAQ Allows Unauthenticated Account Creation via WebAuthn Prepare Endpoint
High
CVE-2026-27836
was published
for
thorsten/phpmyfaq
(Composer)
Feb 27, 2026
Beszel: Docker API has a Path Traversal Vulnerability via Unsanitized Container ID
Moderate
CVE-2026-27734
was published
for
github.com/henrygd/beszel
(Go)
Feb 27, 2026
@actual-app/sync-server: Missing authorization in sync endpoints allows cross-user budget file access in multi-user mode
Moderate
CVE-2026-27638
was published
for
@actual-app/sync-server
(npm)
Feb 27, 2026
Umbraco.Engage.Forms Allows Unauthorized Access to Multiple API Endpoints
High
CVE-2026-27449
was published
for
Umbraco.Engage.Forms
(NuGet)
Feb 27, 2026
Angular i18n vulnerable to Cross-Site Scripting
High
CVE-2026-27970
was published
for
@angular/core
(npm)
Feb 27, 2026
Vitess users with backup storage access can write to arbitrary file paths on restore
Critical
CVE-2026-27969
was published
for
vitess.io/vitess
(Go)
Feb 27, 2026
AWS CLI: cli_history database does not restrict file permissions on Unix systems
Moderate
GHSA-747p-wmpv-9c78
was published
for
awscli
(pip)
Feb 27, 2026
ProTip!
Advisories are also available from the
GraphQL API