GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,630
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,850
Pub
13
RubyGems
1,045
Rust
1,301
Swift
53
Unreviewed advisories
All unreviewed
5,000+
2,099 advisories
Filter by severity
melange has Path Traversal via .PKGINFO in --persist-lint-results
Low
CVE-2026-29051
was published
for
chainguard.dev/melange
(Go)
Apr 23, 2026
pgx: SQL Injection via placeholder confusion with dollar quoted string literals
Low
CVE-2026-41889
was published
for
github.com/jackc/pgx
(Go)
Apr 22, 2026
ps_checkout allows unauthorized method invocation through unvalidated parameter
Low
GHSA-mqq7-wxx5-mp8h
was published
for
prestashop/ps_checkout
(Composer)
Apr 30, 2026
copilot-api has Reliance on Reverse DNS Resolution for a Security-Critical Action
Low
CVE-2026-6874
was published
for
copilot-api
(npm)
Apr 23, 2026
verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()
Low
CVE-2026-6878
was published
for
verl
(pip)
Apr 23, 2026
ydb-go-sdk's transactions are not committed using the `options.WithCommit()` option on last call `table.Transaction.Execute` in transaction
Low
GHSA-28xx-pppm-vqff
was published
for
github.com/ydb-platform/ydb-go-sdk/v3
(Go)
Apr 30, 2026
uutils coreutils has an Incorrect Provision of Specified Functionality Issue in its cut Utility
Low
CVE-2026-35381
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Incorrect Short Circuit Evaluation Issue
Low
CVE-2026-35378
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Incorrect Provision of Specified Functionality Issue
Low
CVE-2026-35379
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Improper Input Validation Issue in its env Utility
Low
CVE-2026-35377
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Improper Handling of Unicode Encoding Issue
Low
CVE-2026-35373
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Improper Handling of Unicode Encoding Issue
Low
CVE-2026-35375
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils's User Interface (UI) Misrepresents Critical Information
Low
CVE-2026-35371
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Incorrect Permission Assignment for Critical Resource
Low
CVE-2026-35367
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Improper Preservation of Permissions issue
Low
CVE-2026-35361
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
Low
CVE-2026-35362
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
Low
CVE-2026-35353
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Unchecked Return Value Issue
Low
CVE-2026-35344
was published
for
coreutils
(Rust)
Apr 22, 2026
coreutils' comm utility silently corrupts data by performing lossy UTF-8 conversion on all output lines
Low
CVE-2026-35346
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Issue With its Always-Incorrect Control Flow Implementation
Low
CVE-2026-35343
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils' mktemp utility doesn't properly handle an empty TMPDIR environment variable
Low
CVE-2026-35342
was published
for
coreutils
(Rust)
Apr 22, 2026
Admidio has CSRF on Admin Preferences that Triggers Unauthorized Backup, .htaccess Write, and Email Send
Low
CVE-2026-41663
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio Leaks Hidden Profile Field Values via Blind Search Oracle in Member Assignment
Low
CVE-2026-41659
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
Low
CVE-2026-22746
was published
for
org.springframework.security:spring-security-core
(Maven)
Apr 22, 2026
Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint
Low
CVE-2026-21388
was published
for
github.com/mattermost/mattermost-plugin-msteams
(Go)
Apr 9, 2026
ProTip!
Advisories are also available from the
GraphQL API