GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,830
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,155
Rust
1,577
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,512
Rust
20
2,484 advisories
Filter by severity
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
High
CVE-2026-85740
was published
for
lightrag-hku
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
High
CVE-2026-77258
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
High
CVE-2026-77247
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: SSRF Protection Bypass
High
CVE-2026-77274
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)
High
CVE-2026-77271
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
mcp-atlassian has an incomplete SSRF remediation
High
CVE-2026-77267
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
High
CVE-2026-77262
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
High
CVE-2026-77259
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches
High
CVE-2026-77261
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)
High
CVE-2026-77260
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths
High
CVE-2026-77257
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
High
CVE-2026-77243
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue
High
CVE-2026-77255
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files
High
CVE-2026-77253
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)
High
CVE-2026-77251
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path
High
CVE-2026-77246
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport
High
CVE-2026-77248
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MPXJ: XXE Vulnerability in MerlinReader
High
CVE-2026-61570
was published
for
MPXJ.Net
(RubyGems)
Sep 22, 2026
psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry
High
CVE-2026-59991
was published
for
psd-tools
(pip)
Sep 22, 2026
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
High
CVE-2026-63349
was published
for
anyio
(pip)
Sep 18, 2026
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
High
CVE-2026-33625
was published
for
lmdeploy
(pip)
Sep 18, 2026
djust: A template binding inherits a context safety grant it never earned (XSS)
High
GHSA-xjw9-38cr-6372
was published
for
djust
(pip)
Sep 17, 2026
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
High
GHSA-9395-2g46-rj3f
was published
for
djust
(pip)
Sep 17, 2026
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
High
CVE-2026-86049
was published
for
jupyter_server
(pip)
Sep 17, 2026
ProTip!
Advisories are also available from the
GraphQL API