GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,450
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,134
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
33,932 advisories
Filter by severity
goshs has ACL Bypass & Path Traversal
Moderate
CVE-2026-66064
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
Pagy I18n locale option is not validated before being used in a file path
Moderate
CVE-2026-54659
was published
for
pagy
(RubyGems)
Jul 28, 2026
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
Moderate
GHSA-6xx4-9wp6-65p7
was published
for
skilo
(Rust)
Jul 28, 2026
Style Dictionary - Prototype Pollution in convertTokenData utility function
High
CVE-2026-54639
was published
for
style-dictionary
(npm)
Jul 28, 2026
openhole-server vulnerable to path traversal via URL-decoded request path
High
CVE-2026-54650
was published
for
github.com/bablilayoub/openhole
(Go)
Jul 28, 2026
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
Critical
CVE-2026-54658
was published
for
@hypequery/clickhouse
(npm)
Jul 28, 2026
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
High
CVE-2026-54638
was published
for
github.com/gotd/td
(Go)
Jul 28, 2026
goshs has a Path Traversal issue
Moderate
CVE-2026-66063
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
Critical
CVE-2026-64863
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
High
CVE-2026-54719
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
Critical
CVE-2026-62325
was published
for
github.com/patrickhener/goshs/v2
(Go)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
High
CVE-2026-54654
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
High
CVE-2026-55389
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
High
CVE-2026-54653
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
High
CVE-2026-55391
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
High
CVE-2026-54656
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
High
CVE-2026-54690
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
High
CVE-2026-55415
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
High
CVE-2026-54621
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
High
CVE-2026-54655
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
Low
CVE-2026-55403
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
High
CVE-2026-54691
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
High
CVE-2026-55390
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
High
CVE-2026-32203
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 28, 2026
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
Moderate
CVE-2026-52888
was published
for
@nocobase/plugin-collection-sql
(npm)
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API