GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,538
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34,560 advisories
Filter by severity
Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root
Moderate
CVE-2026-63123
was published
for
@tinacms/cli
(npm)
Aug 19, 2026
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
Moderate
CVE-2026-59992
was published
for
next-tinacms-azure
(npm)
Aug 19, 2026
logto-tunnel serves files outside --experience-path via path traversal
High
CVE-2026-63188
was published
for
@logto/tunnel
(npm)
Aug 19, 2026
BuildKit has a possible runtime DoS via unbounded group parsing
Low
CVE-2026-61712
was published
for
github.com/moby/buildkit
(Go)
Aug 19, 2026
BuildKit: Custom frontend could bypass Seccomp/AppArmor
Moderate
CVE-2026-61711
was published
for
github.com/moby/buildkit
(Go)
Aug 19, 2026
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
Moderate
GHSA-hjwh-xvfw-qrwj
was published
for
mcp-searxng
(npm)
Aug 19, 2026
Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
High
CVE-2026-62673
was published
for
getgrav/grav
(Composer)
Aug 19, 2026
Snipe-IT: Stored DOM XSS via table selected-count IDs
Moderate
CVE-2026-61807
was published
for
snipe/snipe-it
(Composer)
Aug 19, 2026
Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET
Moderate
CVE-2026-55703
was published
for
snipe/snipe-it
(Composer)
Aug 19, 2026
Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover
High
CVE-2026-55694
was published
for
snipe/snipe-it
(Composer)
Aug 19, 2026
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
High
CVE-2024-45747
was published
for
org.geoserver.web:gs-web-app
(Maven)
Aug 19, 2026
SearXNG MCP Server: Additional hardened-mode SSRF bypasses
Moderate
CVE-2026-54689
was published
for
mcp-searxng
(npm)
Aug 19, 2026
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Moderate
CVE-2026-54688
was published
for
mcp-searxng
(npm)
Aug 19, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing
High
CVE-2026-53966
was published
for
org.xwiki.platform:xwiki-platform-livedata-livetable
(Maven)
Aug 19, 2026
MCP PHP SDK: client HttpTransport SSE buffer (sseBuffer .= chunk) grows unbounded when server withholds the event delimiter
High
CVE-2026-53965
was published
for
mcp/sdk
(Composer)
Aug 19, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
High
CVE-2026-53964
was published
for
document-merge-service
(pip)
Aug 19, 2026
Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
High
CVE-2026-53957
was published
for
@contentful/mcp-server
(npm)
Aug 19, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
High
CVE-2026-53951
was published
for
copier
(pip)
Aug 19, 2026
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
Moderate
CVE-2026-53941
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
Aug 19, 2026
block_buffer: panic corrupts inline buffer position
Moderate
GHSA-qwgh-2vcv-g2f7
was published
for
block_buffer
(Rust)
Aug 19, 2026
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-rr55-jp92-8wp2
was published
for
claude-faf-mcp
(npm)
Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-j4r7-8ph4-43g3
was published
for
faf-mcp
(npm)
Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
High
GHSA-cc2g-gq8c-r332
was published
for
grok-faf-mcp
(npm)
Aug 19, 2026
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
Moderate
CVE-2026-55236
was published
for
langgraph-api
(pip)
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API