GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
7,034 advisories
Filter by severity
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
High
CVE-2026-53608
was published
for
@apostrophecms/seo
(npm)
Jul 31, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Low
CVE-2026-53607
was published
for
apostrophe
(npm)
Jul 31, 2026
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
Critical
CVE-2026-53609
was published
for
apostrophe
(npm)
Jul 31, 2026
sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
Moderate
CVE-2026-53606
was published
for
sanitize-html
(npm)
Jul 31, 2026
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
Critical
CVE-2026-52887
was published
for
@nocobase/plugin-notification-in-app-message
(npm)
Jul 31, 2026
Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
Moderate
CVE-2026-65841
was published
for
jodit
(npm)
Jul 31, 2026
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
High
CVE-2026-58263
was published
for
jodit
(npm)
Jul 31, 2026
Jodit has prototype pollution via Jodit.configure() / ConfigMerge
Moderate
CVE-2026-54756
was published
for
jodit
(npm)
Jul 31, 2026
Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
Moderate
CVE-2026-62324
was published
for
jodit
(npm)
Jul 31, 2026
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
High
CVE-2026-54737
was published
for
@phun-ky/defaults-deep
(npm)
Jul 31, 2026
hashi-vault-js has a path traversal and query parameter injection
High
CVE-2026-55100
was published
for
hashi-vault-js
(npm)
Jul 31, 2026
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
High
CVE-2026-54729
was published
for
dssrf
(npm)
Jul 31, 2026
re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)
Moderate
CVE-2026-67550
was published
for
re2
(npm)
Jul 31, 2026
re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)
Moderate
CVE-2026-68499
was published
for
re2
(npm)
Jul 31, 2026
`nx graph` dev server permissive CORS policy
Moderate
CVE-2026-54753
was published
for
nx
(npm)
Jul 31, 2026
`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
High
GHSA-p7w7-4929-vpj5
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 31, 2026
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
Moderate
GHSA-xrmj-5g4g-8987
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 31, 2026
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
Moderate
GHSA-pqh8-p93p-2rx7
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 31, 2026
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
Critical
CVE-2025-4318
was published
for
@aws-amplify/codegen-ui-react
(npm)
Jul 30, 2026
dssrf has an SSRF bypass with remove_at_symbol_in_string
High
CVE-2026-54722
was published
for
dssrf
(npm)
Jul 30, 2026
mathlive's Lack of Escaping of HTML allows for XSS
Moderate
CVE-2026-54705
was published
for
mathlive
(npm)
Jul 29, 2026
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
High
CVE-2026-11393
was published
for
@aws/agentcore
(npm)
Jul 29, 2026
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
Low
GHSA-pc2w-4mq8-32qw
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
High
CVE-2026-54666
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped enum string values
High
CVE-2026-54664
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
ProTip!
Advisories are also available from the
GraphQL API