GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,824
Maven
5,000+
npm
4,451
NuGet
774
pip
4,218
Pub
12
RubyGems
970
Rust
1,090
Swift
47
Unreviewed advisories
All unreviewed
5,000+
25,423 advisories
Filter by severity
RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`
High
CVE-2026-23519
was published
for
cmov
(Rust)
Jan 15, 2026
Zitadel has a user enumeration vulnerability in Login UIs
Moderate
CVE-2026-23511
was published
for
github.com/zitadel/zitadel
(Go)
Jan 15, 2026
Pimcore Web2Print Tools Bundle "Favourite Output Channel Configuration" Missing Function Level Authorization
Moderate
CVE-2026-23496
was published
for
pimcore/web2print-tools-bundle
(Composer)
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
Moderate
CVE-2026-23495
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Jan 15, 2026
Pimcore is Vulnerable to Broken Access Control: Missing Function Level Authorization on "Static Routes" Listing
Moderate
CVE-2026-23494
was published
for
pimcore/pimcore
(Composer)
Jan 15, 2026
Pimcore ENV Variables and Cookie Informations are exposed in http_error_log
High
CVE-2026-23493
was published
for
pimcore/pimcore
(Composer)
Jan 15, 2026
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
High
CVE-2026-22803
was published
for
@sveltejs/kit
(npm)
Jan 15, 2026
Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse
High
CVE-2026-22774
was published
for
devalue
(npm)
Jan 15, 2026
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
High
CVE-2025-67647
was published
for
@sveltejs/adapter-node
(npm)
Jan 15, 2026
DPanel has an arbitrary file deletion vulnerability in /api/common/attach/delete interface
High
CVE-2025-66292
was published
for
github.com/donknap/dpanel
(Go)
Jan 15, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Moderate
GHSA-595p-g7xc-c333
was published
for
algolia/algoliasearch-magento-2
(Composer)
Jan 14, 2026
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
Low
GHSA-73rr-hh4g-fpgx
was published
for
diff
(npm)
Jan 14, 2026
chi has an open redirect vulnerability in the RedirectSlashes middleware
Moderate
GHSA-mqqf-5wvp-8fh8
was published
for
github.com/go-chi/chi
(Go)
Jan 14, 2026
Pimcore Has an Incomplete Patch for CVE-2023-30848
High
CVE-2026-23492
was published
for
pimcore/pimcore
(Composer)
Jan 14, 2026
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
Low
CVE-2026-22036
was published
for
undici
(npm)
Jan 14, 2026
Shopware Has Improper Control of Generation of Code in Twig rendered views
High
CVE-2026-23498
was published
for
shopware/core
(Composer)
Jan 14, 2026
html2pdf.js contains a cross-site scripting vulnerability
High
CVE-2026-22787
was published
for
html2pdf.js
(npm)
Jan 14, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Moderate
CVE-2026-22779
was published
for
blacksheep
(pip)
Jan 14, 2026
enclave-vm Vulnerable to Sandbox Escape via Host Error Prototype Chain
Critical
CVE-2026-22686
was published
for
enclave-vm
(npm)
Jan 14, 2026
Weblate leaks information via screenshots
Low
CVE-2026-21889
was published
for
weblate
(pip)
Jan 14, 2026
Apache Camel camel-neo4j component is vulnerable to cypher injection
Moderate
CVE-2025-66169
was published
for
org.apache.camel:camel-neo4j
(Maven)
Jan 14, 2026
Chainlit contains an authorization bypass vulnerability
Low
CVE-2025-68492
was published
for
chainlit
(pip)
Jan 14, 2026
Concrete5 CMS contains an XPath injection vulnerability
Moderate
CVE-2022-50807
was published
for
concrete5/concrete5
(Composer)
Jan 14, 2026
go-ethereum is vulnerable to high CPU usage leading to DoS via malicious p2p message
High
CVE-2026-22868
was published
for
github.com/ethereum/go-ethereum
(Go)
Jan 13, 2026
go-ethereum is vulnerable to DoS via malicious p2p message affecting a vulnerable node
High
CVE-2026-22862
was published
for
github.com/ethereum/go-ethereum
(Go)
Jan 13, 2026
ProTip!
Advisories are also available from the
GraphQL API