GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,343
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,550
Pub
12
RubyGems
1,013
Rust
1,203
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,945 advisories
Filter by severity
Home Assistant has stored XSS in history-graphs
Low
CVE-2026-33045
was published
for
homeassistant
(pip)
Mar 27, 2026
Home Assistant has stored XSS in Map-card through malicious device name
Low
CVE-2026-33044
was published
for
homeassistant
(pip)
Mar 27, 2026
Flannel has cross-node remote code execution via extension backend BackendData injection
High
CVE-2026-32241
was published
for
github.com/flannel-io/flannel
(Go)
Mar 27, 2026
A Fleet team maintainer can transfer hosts from any team via missing source team authorization
Moderate
CVE-2026-29180
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 27, 2026
path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters
High
CVE-2026-4867
was published
for
path-to-regexp
(npm)
Mar 27, 2026
Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host
High
CVE-2026-34076
was published
for
@clerk/backend
(npm)
Mar 27, 2026
cryptography has incomplete DNS name constraint enforcement on peer names
Low
CVE-2026-34073
was published
for
cryptography
(pip)
Mar 27, 2026
AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters
High
GHSA-27qh-8cxx-2cr5
was published
for
aws/aws-sdk-php
(Composer)
Mar 27, 2026
LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
High
CVE-2026-34070
was published
for
langchain-core
(pip)
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
CVE-2026-34060
was published
for
ruby-lsp
(RubyGems)
Mar 27, 2026
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
High
CVE-2026-34046
was published
for
langflow
(pip)
Mar 27, 2026
act: actions/cache server allows malicious cache injection
High
CVE-2026-34042
was published
for
github.com/nektos/act
(Go)
Mar 27, 2026
act: Unrestricted set-env and add-path command processing enables environment injection
High
CVE-2026-34041
was published
for
github.com/nektos/act
(Go)
Mar 27, 2026
@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools
High
CVE-2026-33989
was published
for
@mobilenext/mobile-mcp
(npm)
Mar 27, 2026
Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters
High
CVE-2026-33981
was published
for
changedetection.io
(pip)
Mar 27, 2026
Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries
High
CVE-2026-33980
was published
for
adx-mcp-server
(pip)
Mar 27, 2026
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
High
CVE-2026-33946
was published
for
mcp
(RubyGems)
Mar 27, 2026
Saloon has insecure deserialization in AccessTokenAuthenticator
High
CVE-2026-33942
was published
for
saloonphp/saloon
(Composer)
Mar 27, 2026
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
High
CVE-2026-33941
was published
for
handlebars
(npm)
Mar 27, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
High
CVE-2026-33940
was published
for
handlebars
(npm)
Mar 27, 2026
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
High
CVE-2026-33939
was published
for
handlebars
(npm)
Mar 27, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
High
CVE-2026-33938
was published
for
handlebars
(npm)
Mar 27, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion
Critical
CVE-2026-33937
was published
for
handlebars
(npm)
Mar 27, 2026
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
Moderate
CVE-2026-34043
was published
for
serialize-javascript
(npm)
Mar 27, 2026
Fleet's unbounded request body read allows remote Denial of Service
High
CVE-2026-26061
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API