GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
34,638 advisories
Filter by severity
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
Moderate
CVE-2026-67448
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
Moderate
CVE-2026-67447
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
Moderate
CVE-2026-55451
was published
for
gettext-converter
(npm)
Aug 20, 2026
Wagtail: Improper restriction handling on Page translation API endpoint
Moderate
GHSA-jm5p-837g-rv8g
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Improper permission handling when copying snippets
Moderate
GHSA-x5cx-w6p2-mxf2
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Improper restriction handling on descendant collections in Documents and Images API
Moderate
GHSA-c2xx-cjmh-9q8f
was published
for
wagtail
(pip)
Aug 20, 2026
Wagtail: Identification of documents by SHA1 hash
Low
GHSA-92hv-j533-69wc
was published
for
wagtail
(pip)
Aug 20, 2026
Winter: Reflected XSS through the search query parameter in the backend Table widget
Moderate
GHSA-hq84-x37p-j6q5
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Winter: CSRF through AJAX handler names reachable as backend page actions
Moderate
GHSA-p2ch-c2c3-4xm5
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles
Moderate
GHSA-5cwr-5jxg-pcf6
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
Moderate
GHSA-fm29-4mq3-phg6
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Winter: My Account preview exposes another backend user's profile by record ID
Moderate
GHSA-mpmw-f6h6-3g26
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Winter: Stored XSS through Backend List widget image columns
Low
GHSA-7mpf-4465-7fc2
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Fleet: ORDER BY column injection on activity list endpoints
Low
GHSA-rxhg-vcww-2mpw
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 20, 2026
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
Moderate
GHSA-q9c5-pp7m-fm2g
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 20, 2026
Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)
High
GHSA-8cfw-pcwh-v63w
was published
for
winter/wn-system-module
(Composer)
Aug 20, 2026
Winter: Local File Inclusion through =include directives in JavaScript asset compilation
Moderate
GHSA-2223-f22x-24cq
was published
for
winter/wn-system-module
(Composer)
Aug 20, 2026
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
High
CVE-2026-63202
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets
Moderate
CVE-2026-63179
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
High
CVE-2026-61827
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
High
CVE-2026-63124
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
Moderate
CVE-2026-61799
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
High
CVE-2026-61798
was published
for
io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl
(Maven)
Aug 20, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
Moderate
CVE-2026-61663
was published
for
django-cms
(pip)
Aug 20, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
Moderate
CVE-2026-63003
was published
for
django-cms
(pip)
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API