GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,052 advisories
Filter by severity
adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
High
GHSA-rcw4-f5rp-g42v
was published
for
adm-zip
(npm)
Sep 29, 2026
adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
High
CVE-2026-102282
was published
for
adm-zip
(npm)
Sep 29, 2026
Laravel: XSS in Debug Page Information
Low
CVE-2026-102279
was published
for
laravel/framework
(Composer)
Sep 29, 2026
Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
Moderate
GHSA-8vvx-rff5-p5rq
was published
for
nodemailer
(npm)
Sep 29, 2026
PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
Moderate
CVE-2026-102274
was published
for
PyJWT
(pip)
Sep 29, 2026
undici vulnerable to Denial of Service via orphaned RetryHandler response body
Moderate
CVE-2026-18149
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to downstream response splitting via retry interceptor
Low
CVE-2026-18540
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
High
CVE-2026-19534
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to Denial of Service via unbounded decompression of compressed responses
Moderate
CVE-2026-84890
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
Moderate
CVE-2026-84933
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
Low
CVE-2026-84947
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
High
CVE-2026-84961
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to caching and replay of unsafe HTTP method responses
Low
CVE-2026-85008
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
High
CVE-2026-85152
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to Denial of Service via WebSocketStream unclean close
Moderate
CVE-2026-85014
was published
for
undici
(npm)
Sep 29, 2026
Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check is bypassed by malformed UTF-8 in the path, affecting every adapter
Low
CVE-2026-102601
was published
for
league/flysystem
(Composer)
Sep 29, 2026
joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
High
GHSA-6h2x-m376-mqjq
was published
for
joi
(npm)
Sep 29, 2026
Electron: Local race condition in Squirrel.Mac update installation on macOS
Moderate
CVE-2026-102672
was published
for
electron
(npm)
Sep 29, 2026
Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
High
CVE-2026-102673
was published
for
electron
(npm)
Sep 29, 2026
Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
High
CVE-2026-102674
was published
for
electron
(npm)
Sep 29, 2026
Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
High
CVE-2026-102675
was published
for
electron
(npm)
Sep 29, 2026
Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions
High
CVE-2026-102676
was published
for
electron
(npm)
Sep 29, 2026
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
High
CVE-2026-102677
was published
for
electron
(npm)
Sep 29, 2026
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Moderate
CVE-2026-81872
was published
for
go.opentelemetry.io/otel/sdk/log
(Go)
Sep 29, 2026
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
Moderate
CVE-2026-81869
was published
for
go.opentelemetry.io/otel/sdk
(Go)
Sep 29, 2026
ProTip!
Advisories are also available from the
GraphQL API