GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
2,891
Erlang
24
GitHub Actions
39
Go
2,240
Maven
2,698
npm
2,899
NuGet
500
pip
2,728
Pub
5
RubyGems
364
Rust
889
Swift
19
Unreviewed advisories
All unreviewed
5,000+
15,098 advisories
Filter by severity
Spinnaker: RCE via expression parsing due to unrestricted context handling
Critical
CVE-2026-32613
was published
for
io.spinnaker.echo:echo-pipelinetriggers
(Maven)
Apr 21, 2026
Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
Critical
CVE-2026-32604
was published
for
io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo
(Maven)
Apr 21, 2026
python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
Moderate
CVE-2026-28684
was published
for
python-dotenv
(pip)
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
Moderate
CVE-2026-25525
was published
for
openmage/magento-lts
(Composer)
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
High
CVE-2026-25524
was published
for
openmage/magento-lts
(Composer)
Apr 21, 2026
RAGAS has SSRF via Multi-Modal Faithfulness Collections Module
Low
CVE-2026-6587
was published
for
ragas
(pip)
Apr 20, 2026
apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation
Moderate
CVE-2026-40948
was published
for
apache-airflow-providers-keycloak
(pip)
Apr 18, 2026
Apache Airflow allows code execution through crafted XCom payloads
Critical
CVE-2026-25917
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
Moderate
CVE-2026-30912
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Low
CVE-2026-32690
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
High
CVE-2026-32228
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
Zebra Vulnerable to Consensus Divergence in Transparent Sighash Hash-Type Handling
Critical
GHSA-8m29-fpq5-89jj
was published
for
zebra-script
(Rust)
Apr 18, 2026
Zebra Vulnerable to Denial of Service via Interrupted JSON-RPC Requests from Authenticated Clients
Moderate
GHSA-29x4-r6jv-ff4w
was published
for
zebra-rpc
(Rust)
Apr 18, 2026
Zebra has rk Identity Point Panic in Transaction Verification
Critical
GHSA-452v-w3gx-72wg
was published
for
zebra-chain
(Rust)
Apr 18, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
Moderate
GHSA-9j88-vvj5-vhgr
was published
for
MailKit
(NuGet)
Apr 18, 2026
pretalx vulnerable to stored cross-site scripting in organizer search typeahead
High
GHSA-cjcx-jfp2-f7m2
was published
for
pretalx
(pip)
Apr 18, 2026
pretalx mail templates vulnerable to email injection via unescaped user-controlled placeholders
Moderate
GHSA-jm8c-9f3j-4378
was published
for
pretalx
(pip)
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
Critical
GHSA-xjvp-7243-rg9h
was published
for
charm.land/wish/v2
(Go)
Apr 18, 2026
Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
High
GHSA-mjw2-v2hm-wj34
was published
for
dagster
(pip)
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Moderate
CVE-2026-6437
was published
for
github.com/kubernetes-sigs/aws-efs-csi-driver
(Go)
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
Moderate
CVE-2026-41078
was published
for
OpenTelemetry.Exporter.Jaeger
(NuGet)
Apr 18, 2026
YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()
High
GHSA-f58v-p6j9-24c2
was published
for
yeswiki/yeswiki
(Composer)
Apr 18, 2026
Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass
Critical
GHSA-6g38-8j4p-j3pr
was published
for
github.com/nhost/nhost
(Go)
Apr 18, 2026
PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes
High
GHSA-qrr6-mg7r-m243
was published
for
phpunit/phpunit
(Composer)
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
Low
GHSA-h39g-6x3c-7fq9
was published
for
Zio
(NuGet)
Apr 18, 2026
ProTip!
Advisories are also available from the
GraphQL API