GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
165 advisories
Filter by severity
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
Moderate
GHSA-xrmj-5g4g-8987
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 31, 2026
A Server-Side Template Injection (SSTI) vulnerability was identified
in the mail template...
Critical
Unreviewed
CVE-2026-9177
was published
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
High
CVE-2026-54666
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped enum string values
High
CVE-2026-54664
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
High
CVE-2026-54661
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
High
CVE-2026-54662
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
High
CVE-2026-54654
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
High
CVE-2026-54653
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
High
CVE-2026-54621
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
Oh My Posh: Arbitrary command execution via template injection in the path segment
High
GHSA-6xj8-qv9j-xcjq
was published
for
github.com/jandedobbeleer/oh-my-posh
(Go)
Jul 24, 2026
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Critical
GHSA-w28w-gp39-m4p6
was published
for
@prompty/core
(npm)
Jul 24, 2026
Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who...
High
Unreviewed
CVE-2026-63728
was published
Jul 21, 2026
YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
High
CVE-2026-52762
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
Formie Hidden field defaults vulnerable to Server-Side Template Injection
Critical
CVE-2026-52889
was published
for
verbb/formie
(Composer)
Jul 6, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
Critical
CVE-2026-9558
was published
for
mautic/core
(Composer)
Jul 2, 2026
GeoNetwork has reflected XSS through client-side template injection
High
CVE-2026-39379
was published
for
org.geonetwork-opensource:geonetwork
(Maven)
Jul 1, 2026
Gogs has DoS in rendering issue index pattern
Low
CVE-2026-52796
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability...
Critical
Unreviewed
CVE-2026-54390
was published
Jun 18, 2026
Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
High
CVE-2026-11407
was published
for
pimcore/pimcore
(Composer)
Jun 17, 2026
Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection resulting in Remote Code Execution
Critical
CVE-2026-44181
was published
for
jupyter_enterprise_gateway
(pip)
Jun 3, 2026
Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to...
Critical
Unreviewed
CVE-2026-34906
was published
Jun 2, 2026
Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
Critical
CVE-2026-42252
was published
for
apache-airflow
(pip)
Jun 1, 2026
In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in...
Moderate
Unreviewed
CVE-2026-49382
was published
May 29, 2026
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
High
CVE-2026-46439
was published
for
compliance-trestle
(pip)
May 28, 2026
An Angular template injection vulnerability was discovered in the Reports functionality due to...
Moderate
Unreviewed
CVE-2025-40900
was published
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API