GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,920
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
36,744 advisories
Filter by severity
pyload-ng: getUserData/get_userdata exposed at Perms.ANY allow any authenticated account to brute-force the administrator password
High
GHSA-68w4-83fh-f2w8
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header
Moderate
GHSA-9q47-3cm2-2rp8
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Privilege revocation and password change through the REST API do not invalidate the user's session
High
GHSA-jq7h-wrvp-3rgx
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Api.set_user_permission never invalidates the target's session
High
GHSA-889w-m37p-88m5
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad WindowsPhoneNotify addon: non-admin SETTINGS user triggers SSRF via unguarded http.client notification host
Moderate
GHSA-p3pr-8f3m-4qp8
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Tar extraction creates device nodes and FIFOs (member types not filtered; tarfile extractall without filter=)
High
GHSA-fr26-jjhm-638c
was published
for
pyload-ng
(pip)
Oct 9, 2026
Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE via a compromised mirror or MITM
High
CVE-2026-107812
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
Nginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass)
High
CVE-2026-107808
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs
High
CVE-2026-107809
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in RequireSecureSession, so those sensitive mutations run without OTP step-up
High
CVE-2026-107813
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation as initUser
High
CVE-2026-107811
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
Nginx UI: Node Secret Credential Exposure via URL Query Parameter
High
CVE-2026-107807
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path before restore flags are applied
High
CVE-2026-107810
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
pyLoad has an authentication bypass in API key validation (check_apikey cache)
High
GHSA-r44w-v6gf-x3p6
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo
Moderate
CVE-2026-75597
was published
for
pyload-ng
(pip)
Oct 9, 2026
Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL
High
CVE-2026-55797
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Oct 9, 2026
pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination
Moderate
CVE-2026-48484
was published
for
pyload-ng
(pip)
Oct 9, 2026
Strawberry legacy graphql-ws retains naturally completed subscription slots
Low
CVE-2026-107727
was published
for
strawberry-graphql
(pip)
Oct 9, 2026
Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy
High
CVE-2026-107728
was published
for
strawberry-graphql
(pip)
Oct 9, 2026
fast-jwt: Verifier cache accepts expired JWTs without iat.
Moderate
CVE-2026-107719
was published
for
fast-jwt
(npm)
Oct 8, 2026
Hazelcast allows arbitrary member memory access by low-privileged client
Critical
CVE-2026-107726
was published
for
com.hazelcast:hazelcast
(Maven)
Oct 8, 2026
Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry
Moderate
CVE-2026-107716
was published
for
banks
(pip)
Oct 8, 2026
Banks: User-controlled prompt input can be parsed as privileged chat messages
Moderate
CVE-2026-107717
was published
for
banks
(pip)
Oct 8, 2026
Indico: Incomplete Server-Side Request Forgery (SSRF) check
Moderate
CVE-2026-107394
was published
for
indico
(pip)
Oct 8, 2026
Indico: Missing access check in legacy session export API
Moderate
CVE-2026-107395
was published
for
indico
(pip)
Oct 8, 2026
ProTip!
Advisories are also available from the
GraphQL API