GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,880
Maven
5,000+
npm
5,000+
NuGet
958
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,364
Swift
54
Unreviewed advisories
All unreviewed
5,000+
13,548 advisories
Filter by severity
Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows
Moderate
GHSA-c2c9-mfw7-p8hw
was published
for
flowise
(npm)
May 20, 2026
Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification
Moderate
GHSA-59fh-9f3p-7m39
was published
for
flowise
(npm)
May 20, 2026
Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage
Moderate
GHSA-m837-xvxr-vqwg
was published
for
flowise
(npm)
May 20, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
Moderate
CVE-2026-46431
was published
for
github.com/xyproto/algernon
(Go)
May 20, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
Moderate
CVE-2026-46430
was published
for
github.com/xyproto/algernon
(Go)
May 20, 2026
Setup PHP: GitHub tokens configured by setup-php may be exposed through pinned affected Composer versions
Moderate
GHSA-5wxr-w449-57cm
was published
for
shivammathur/setup-php
(GitHub Actions)
May 20, 2026
Setup PHP: Command Injection in Repository-Derived PHP Version Resolution
Moderate
CVE-2026-46420
was published
for
shivammathur/setup-php
(GitHub Actions)
May 20, 2026
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
Moderate
CVE-2026-45792
was published
for
rtk
(Rust)
May 20, 2026
Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
Moderate
CVE-2026-46338
was published
for
pymdown-extensions
(pip)
May 19, 2026
FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
Moderate
CVE-2026-45802
was published
for
setasign/fpdi
(Composer)
May 19, 2026
Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint
Moderate
CVE-2026-45796
was published
for
github.com/coder/coder
(Go)
May 19, 2026
HAX CMS: Denial of Service using Malicious Import Request
Moderate
CVE-2026-46357
was published
for
@haxtheweb/haxcms-nodejs
(npm)
May 19, 2026
OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle
Moderate
CVE-2026-45785
was published
for
OpenMcdf
(NuGet)
May 19, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Moderate
CVE-2026-45784
was published
for
openssl
(Rust)
May 19, 2026
Trubo: Login callback CSRF/session fixation
Moderate
CVE-2026-45773
was published
for
turbo
(npm)
May 19, 2026
Diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`
Moderate
GHSA-m9p2-fxp5-v3fp
was published
for
diesel
(Rust)
May 19, 2026
Diesel: Possible unaligned data access for implementations of `SqliteAggregate`
Moderate
GHSA-q8x8-jrhj-fh9p
was published
for
diesel
(Rust)
May 19, 2026
Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
Moderate
GHSA-gx7w-56w6-g48x
was published
for
github.com/caddyserver/caddy/v2
(Go)
May 19, 2026
Caddy CVE-2026-30852 Fix Bypass
Moderate
GHSA-wwhq-w58m-w29c
was published
for
github.com/caddyserver/caddy/v2
(Go)
May 19, 2026
Kong Ingress Controller for Kubernetes (KIC): Cross-namespace TLS Secret Exfiltration in Gateways with GatewayClass missing `konghq.com/gatewayclass-unmanaged: 'true'` annotation
Moderate
GHSA-m23h-6mwm-39m8
was published
for
github.com/kong/kubernetes-ingress-controller
(Go)
May 19, 2026
Kong Ingress Controller for Kubernetes (KIC): Secret-backed plugin configurations leak through non-sensitive diagnostics endpoint
Moderate
GHSA-3278-c88v-xrh4
was published
for
github.com/kong/kubernetes-ingress-controller
(Go)
May 19, 2026
Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
Moderate
CVE-2026-46341
was published
for
@apify/actors-mcp-server
(npm)
May 19, 2026
Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour
Moderate
CVE-2026-46424
was published
for
@budibase/backend-core
(npm)
May 19, 2026
AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
Moderate
CVE-2026-46337
was published
for
WWBN/AVideo
(Composer)
May 19, 2026
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
Moderate
CVE-2026-45740
was published
for
protobufjs
(npm)
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API