GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,653
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,860
Pub
13
RubyGems
1,050
Rust
1,304
Swift
53
Unreviewed advisories
All unreviewed
5,000+
124,187 advisories
Filter by severity
Improper privilege management in the log rotation mechanism of the Skylight Workspace Config...
High
Unreviewed
CVE-2026-7791
was published
May 5, 2026
Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a...
High
Unreviewed
CVE-2026-7776
was published
May 5, 2026
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
High
CVE-2026-42033
was published
for
axios
(npm)
May 5, 2026
Axios: Header Injection via Prototype Pollution
High
CVE-2026-42035
was published
for
axios
(npm)
May 5, 2026
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
High
CVE-2026-42043
was published
for
axios
(npm)
May 5, 2026
Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
High
CVE-2026-42264
was published
for
axios
(npm)
May 5, 2026
webonyx/graphql-php has quadratic validation cost in OverlappingFieldsCanBeMerged via inline fragments
High
GHSA-fc86-6rv6-2jpm
was published
for
webonyx/graphql-php
(Composer)
May 4, 2026
livewire-markdown-editor has arbitrary file upload that allows stored XSS via attachment handler
High
GHSA-gxxh-8vcj-w2mh
was published
for
mckenziearts/livewire-markdown-editor
(Composer)
May 4, 2026
pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy via unrestricted `proxy.*` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586)
High
CVE-2026-42313
was published
for
pyload-ng
(pip)
May 4, 2026
net-imap vulnerable to STARTTLS stripping via invalid response timing
High
CVE-2026-42246
was published
for
net-imap
(RubyGems)
May 4, 2026
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow...
High
Unreviewed
CVE-2026-41927
was published
May 4, 2026
Conditional Fields for Contact Form 7 WordPress plugin through version 2.6.7 contains an...
High
Unreviewed
CVE-2026-25863
was published
May 4, 2026
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
High
CVE-2026-42575
was published
for
chainguard.dev/apko
(Go)
May 4, 2026
apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root
High
CVE-2026-42574
was published
for
chainguard.dev/apko
(Go)
May 4, 2026
AzuraCast Vulnerable to Liquidsoap Code Injection via Incomplete cleanUpString-to-toRawString Migration in Remote Relay Password Field
High
GHSA-q4ph-8x8g-95f8
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
AzuraCast has Password Reset Poisoning via Untrusted X-Forwarded-Host Header that Leads to Account Takeover and 2FA Bypass
High
CVE-2026-42606
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
AzuraCast has Path Traversal in `currentDirectory` Parameter that Enables Remote Code Execution via Media Upload
High
CVE-2026-42605
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root
High
GHSA-wppj-c6mr-83jj
was published
for
openclaw
(npm)
May 4, 2026
changedetection.io project has an XXE vulnerability
High
CVE-2026-41895
was published
for
changedetection.io
(pip)
May 4, 2026
Signal K Server's WebSocket Login Endpoint Lacks Rate Limiting (Credential Brute-Force)
High
CVE-2026-41893
was published
for
signalk-server
(npm)
May 4, 2026
OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens
High
GHSA-r6xh-pqhr-v4xh
was published
for
openclaw
(npm)
May 4, 2026
Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
High
CVE-2026-42311
was published
for
pillow
(pip)
May 4, 2026
pyp2spec is Vulnerable to Code Injection
High
CVE-2026-42301
was published
for
pyp2spec
(pip)
May 4, 2026
Argo vulnerable to exposure of artifact repository credentials
High
CVE-2026-42295
was published
for
github.com/argoproj/argo-workflows/v4
(Go)
May 4, 2026
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure
High
CVE-2026-42296
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
May 4, 2026
ProTip!
Advisories are also available from the
GraphQL API