GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,753
Maven
5,000+
npm
5,000+
NuGet
1,117
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,573
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
35,603 advisories
Filter by severity
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
Moderate
CVE-2026-61709
was published
for
github.com/openfga/openfga
(Go)
Sep 16, 2026
Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
Moderate
CVE-2026-58657
was published
for
getgrav/grav
(Composer)
Sep 16, 2026
@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
High
CVE-2026-63671
was published
for
@nuxtjs/mdc
(npm)
Sep 16, 2026
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
High
CVE-2026-63128
was published
for
rmcp
(Rust)
Sep 16, 2026
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
High
CVE-2026-63127
was published
for
rmcp
(Rust)
Sep 16, 2026
Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
Moderate
CVE-2026-61453
was published
for
getgrav/grav
(Composer)
Sep 16, 2026
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
Moderate
CVE-2026-57173
was published
for
vllm
(pip)
Sep 16, 2026
Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()
Moderate
CVE-2026-59193
was published
for
getgrav/grav
(Composer)
Sep 16, 2026
djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path
High
CVE-2026-61599
was published
for
djust
(pip)
Sep 16, 2026
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
Moderate
CVE-2026-61589
was published
for
djust
(pip)
Sep 16, 2026
djust has broken object-level access control (IDOR)
High
CVE-2026-61596
was published
for
djust
(pip)
Sep 16, 2026
djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
Moderate
CVE-2026-61588
was published
for
djust
(pip)
Sep 16, 2026
djust has an authorization bypass on the WebSocket/SSE mount path
Critical
CVE-2026-61594
was published
for
djust
(pip)
Sep 16, 2026
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
High
CVE-2026-61591
was published
for
djust
(pip)
Sep 16, 2026
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
High
CVE-2026-61592
was published
for
djust
(pip)
Sep 16, 2026
djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
Moderate
CVE-2026-61597
was published
for
djust
(pip)
Sep 16, 2026
node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion
High
CVE-2026-68904
was published
for
node-opcua
(npm)
Sep 16, 2026
djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
High
CVE-2026-61593
was published
for
djust
(pip)
Sep 16, 2026
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
Critical
CVE-2025-59953
was published
for
lmdeploy
(pip)
Sep 16, 2026
djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data
High
CVE-2026-61595
was published
for
djust
(pip)
Sep 16, 2026
djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler
High
CVE-2026-61598
was published
for
djust
(pip)
Sep 16, 2026
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
High
CVE-2026-81192
was published
for
OpenTelemetry.Resources.Host
(NuGet)
Sep 16, 2026
djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
High
CVE-2026-61590
was published
for
djust
(pip)
Sep 16, 2026
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
Critical
CVE-2026-61560
was published
for
@zereight/mcp-gitlab
(npm)
Sep 16, 2026
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
Critical
CVE-2026-61559
was published
for
@zereight/mcp-gitlab
(npm)
Sep 15, 2026
ProTip!
Advisories are also available from the
GraphQL API