GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,798
Maven
5,000+
npm
4,424
NuGet
772
pip
4,192
Pub
12
RubyGems
968
Rust
1,083
Swift
46
Unreviewed advisories
All unreviewed
5,000+
25,306 advisories
Filter by severity
Authlib has 1-click Account Takeover vulnerability
Moderate
CVE-2025-68158
was published
for
authlib
(pip)
Jan 8, 2026
AWS SDK for Swift adopted defense in depth enhancement for region parameter value
Low
GHSA-pc9j-5v36-2mww
was published
for
github.com/awslabs/aws-sdk-swift
(Swift)
Jan 8, 2026
JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3
Low
GHSA-j965-2qgj-vjmq
was published
for
aws-sdk
(npm)
Jan 8, 2026
AWS SDK for JavaScript v3 adopted defense in depth enhancement for region parameter value
Low
GHSA-6475-r3vj-m8vf
was published
for
@smithy/config-resolver
(npm)
Jan 8, 2026
vLLM introduced enhanced protection for CVE-2025-62164
High
GHSA-mcmc-2m55-j8jj
was published
for
vllm
(pip)
Jan 8, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
Low
GHSA-g59m-gf8j-gjf5
was published
for
aws-sdk-accessanalyzer
(Rust)
Jan 8, 2026
Ghost has SQL Injection in Members Activity Feed
Moderate
CVE-2026-22596
was published
for
ghost
(npm)
Jan 8, 2026
Ghost has SSRF via External Media Inliner
Moderate
CVE-2026-22597
was published
for
ghost
(npm)
Jan 8, 2026
Ghost has Staff Token permission bypass
High
CVE-2026-22595
was published
for
ghost
(npm)
Jan 8, 2026
Spree API has Unauthenticated IDOR - Guest Address
High
CVE-2026-22589
was published
for
spree_core
(RubyGems)
Jan 8, 2026
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
Moderate
CVE-2026-22588
was published
for
spree_api
(RubyGems)
Jan 8, 2026
Salvo is vulnerable to reflected XSS in the list_html function
High
CVE-2026-22256
was published
for
salvo
(Rust)
Jan 8, 2026
Salvo is vulnerable to stored XSS in the list_html function by uploading files with malicious names
High
CVE-2026-22257
was published
for
salvo
(Rust)
Jan 8, 2026
Shakapacker has environment variable leak via EnvironmentPlugin that exposes secrets to client-side bundles
High
GHSA-96qw-h329-v5rg
was published
for
shakapacker
(RubyGems)
Jan 8, 2026
Soft Serve is missing an authorization check in LFS lock deletion
Moderate
CVE-2026-22253
was published
for
github.com/charmbracelet/soft-serve
(Go)
Jan 8, 2026
React Router has CSRF issue in Action/Server Action Request Processing
Moderate
CVE-2026-22030
was published
for
@remix-run/server-runtime
(npm)
Jan 8, 2026
React Router vulnerable to XSS via Open Redirects
High
CVE-2026-22029
was published
for
@remix-run/router
(npm)
Jan 8, 2026
React Router SSR XSS in ScrollRestoration
High
CVE-2026-21884
was published
for
@remix-run/react
(npm)
Jan 8, 2026
React Router has unexpected external redirect via untrusted paths
Moderate
CVE-2025-68470
was published
for
react-router
(npm)
Jan 8, 2026
React Router has Path Traversal in File Session Storage
Critical
CVE-2025-61686
was published
for
@react-router/node
(npm)
Jan 8, 2026
React Router has XSS Vulnerability
High
CVE-2025-59057
was published
for
@remix-run/react
(npm)
Jan 8, 2026
RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting
Moderate
CVE-2026-22043
was published
for
rustfs
(Rust)
Jan 8, 2026
RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation
Moderate
CVE-2026-22042
was published
for
rustfs
(Rust)
Jan 8, 2026
Kirby is missing permission checks in the content changes API
Moderate
CVE-2026-21896
was published
for
getkirby/cms
(Composer)
Jan 8, 2026
ProTip!
Advisories are also available from the
GraphQL API