GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,562
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,807
Pub
13
RubyGems
1,038
Rust
1,238
Swift
53
Unreviewed advisories
All unreviewed
5,000+
29,254 advisories
Filter by severity
Astro: XSS in define:vars via incomplete </script> tag sanitization
Moderate
CVE-2026-41067
was published
for
astro
(npm)
Apr 21, 2026
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
High
CVE-2026-41066
was published
for
lxml
(pip)
Apr 21, 2026
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
High
CVE-2026-40938
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
Moderate
CVE-2026-40924
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check
Moderate
CVE-2026-40923
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Critical
CVE-2026-41264
was published
for
flowise
(npm)
Apr 21, 2026
Brillig: Heap corruption in foreign call results with nested tuple arrays
Critical
CVE-2026-41197
was published
for
brillig
(Rust)
Apr 21, 2026
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation
Moderate
CVE-2026-40343
was published
for
github.com/free5gc/udr
(Go)
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
CVE-2026-40488
was published
for
openmage/magento-lts
(Composer)
Apr 21, 2026
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
High
CVE-2026-40161
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace
High
CVE-2026-39861
was published
for
@anthropic-ai/claude-code
(npm)
Apr 21, 2026
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
Low
CVE-2026-40264
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenBao's SQL Injection in PostgreSQL database secrets engine
Moderate
CVE-2026-39946
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
Low
CVE-2026-39396
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
Low
CVE-2026-39388
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
Neko has a Self-service Privilege Escalation for Authenticated Users
High
CVE-2026-39386
was published
for
github.com/m1k1o/neko/server
(Go)
Apr 21, 2026
nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
Moderate
CVE-2026-39378
was published
for
nbconvert
(pip)
Apr 21, 2026
nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
Moderate
CVE-2026-39377
was published
for
nbconvert
(pip)
Apr 21, 2026
Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths
High
CVE-2026-39320
was published
for
signalk-server
(npm)
Apr 21, 2026
October CMS: Editor Sub-Permission Bypass for Asset and Blueprint File Operations
Low
CVE-2026-29179
was published
for
october/system
(Composer)
Apr 21, 2026
October CMS: Reflected XSS via DataTable Form Widget
Low
CVE-2026-27937
was published
for
october/system
(Composer)
Apr 21, 2026
October CMS has Safe Mode Bypass via Twig Database Write Operations
Moderate
CVE-2026-26274
was published
for
october/october
(Composer)
Apr 21, 2026
October CMS has Safe Mode Bypass via CSS Preprocessor Compilers
Moderate
CVE-2026-26067
was published
for
october/system
(Composer)
Apr 21, 2026
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
Moderate
CVE-2026-25542
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Auth0 Next.js SDK has Improper Proxy Cache Lookup
Moderate
CVE-2026-40155
was published
for
@auth0/nextjs-auth0
(npm)
Apr 21, 2026
ProTip!
Advisories are also available from the
GraphQL API