GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,830
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,155
Rust
1,577
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
12,937 advisories
Filter by severity
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
High
CVE-2026-77633
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
High
CVE-2026-94462
was published
for
spree_api
(RubyGems)
Sep 22, 2026
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
High
CVE-2026-85740
was published
for
lightrag-hku
(pip)
Sep 22, 2026
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
High
CVE-2026-76819
was published
for
github.com/projectdiscovery/nuclei/v3
(Go)
Sep 22, 2026
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for
High
CVE-2026-77560
was published
for
github.com/tinyauthapp/tinyauth
(Go)
Sep 22, 2026
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API
High
CVE-2026-62371
was published
for
github.com/kubeedge/kubeedge
(Go)
Sep 22, 2026
KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join
High
CVE-2026-62369
was published
for
github.com/kubeedge/kubeedge
(Go)
Sep 22, 2026
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
High
CVE-2026-71543
was published
for
github.com/openbao/openbao
(Go)
Sep 22, 2026
KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes
High
CVE-2026-62182
was published
for
github.com/kubeedge/kubeedge
(Go)
Sep 22, 2026
Unleash: Missing await on permission check + cross-project IDOR in admin API
High
CVE-2026-77426
was published
for
unleash-server
(npm)
Sep 22, 2026
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
High
CVE-2026-77258
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
High
CVE-2026-77247
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: SSRF Protection Bypass
High
CVE-2026-77274
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)
High
CVE-2026-77271
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
mcp-atlassian has an incomplete SSRF remediation
High
CVE-2026-77267
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
High
CVE-2026-77262
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
High
CVE-2026-77259
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches
High
CVE-2026-77261
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)
High
CVE-2026-77260
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths
High
CVE-2026-77257
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
High
CVE-2026-77243
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue
High
CVE-2026-77255
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files
High
CVE-2026-77253
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)
High
CVE-2026-77251
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path
High
CVE-2026-77246
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
ProTip!
Advisories are also available from the
GraphQL API