GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
3,983
Maven
5,000+
npm
5,000+
NuGet
973
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,387
Swift
56
Unreviewed advisories
All unreviewed
5,000+
31,456 advisories
Filter by severity
Netty: SCTP reassembly nests buffers without bound
High
CVE-2026-46340
was published
for
io.netty:netty-transport-sctp
(Maven)
Jun 8, 2026
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
High
CVE-2026-45674
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
Moderate
CVE-2026-45673
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
Netty: Unix-socket fd receive leaks descriptors when peer sends two at once
Moderate
CVE-2026-45536
was published
for
io.netty:netty-transport-native-epoll
(Maven)
Jun 8, 2026
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
High
CVE-2026-45416
was published
for
io.netty:netty-handler
(Maven)
Jun 8, 2026
PHPSpreadsheet has a patch bypass for CVE-2026-34084
Critical
CVE-2026-45034
was published
for
phpoffice/phpspreadsheet
(Composer)
Jun 8, 2026
Netty's Default QUIC token handler accepts any client-supplied token
High
CVE-2026-44894
was published
for
io.netty:netty-codec-classes-quic
(Maven)
Jun 8, 2026
Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
High
CVE-2026-44893
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jun 8, 2026
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
High
CVE-2026-44892
was published
for
io.netty:netty-codec-http3
(Maven)
Jun 8, 2026
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
High
CVE-2026-44890
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 8, 2026
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
High
CVE-2026-44250
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 8, 2026
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
High
CVE-2026-44249
was published
for
io.netty:netty-handler
(Maven)
Jun 8, 2026
actual Allows Electron to Run As Node
Moderate
CVE-2026-42890
was published
for
actual
(npm)
Jun 8, 2026
Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type
Moderate
CVE-2026-41479
was published
for
authlib
(pip)
Jun 8, 2026
GeoNode contains a server-side request forgery vulnerability in the service registration endpoint
Moderate
CVE-2026-39922
was published
for
geonode
(pip)
Jun 8, 2026
Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
High
CVE-2026-47732
was published
for
twig/twig
(Composer)
Jun 5, 2026
Twig: XSS in profiler HtmlDumper via unescaped template and profile names
Low
CVE-2026-47730
was published
for
twig/twig
(Composer)
Jun 5, 2026
Bugsink: DOS using large numbers of event tags
Moderate
GHSA-5x67-j5xg-c5gj
was published
for
bugsink
(pip)
Jun 5, 2026
Bugsink: Project scoping missing in sourcemap and debug-file lookup
Moderate
CVE-2026-47728
was published
for
bugsink
(pip)
Jun 5, 2026
Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
Low
CVE-2026-47716
was published
for
bugsink
(pip)
Jun 5, 2026
Bugsink: Issue event views can show an event from another project if its UUID is known
Low
CVE-2026-47715
was published
for
bugsink
(pip)
Jun 5, 2026
Twig: Possible sandbox bypass when using a source policy
High
CVE-2026-24425
was published
for
twig/twig
(Composer)
Jun 5, 2026
Shopper: Authorization bypass and RBAC privilege escalation in team settings
Critical
CVE-2026-47744
was published
for
shopper/framework
(Composer)
Jun 5, 2026
Shopper: Multiple data integrity and disclosure issues in admin Livewire components
High
CVE-2026-47743
was published
for
shopper/framework
(Composer)
Jun 5, 2026
Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tables
Moderate
CVE-2026-47745
was published
for
shopper/framework
(Composer)
Jun 5, 2026
ProTip!
Advisories are also available from the
GraphQL API