GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
66 advisories
Filter by severity
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
Critical
CVE-2026-61682
was published
for
github.com/kcp-dev/kcp
(Go)
Sep 18, 2026
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
Moderate
CVE-2026-61589
was published
for
djust
(pip)
Sep 16, 2026
Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue...
Moderate
Unreviewed
CVE-2026-90679
was published
Sep 13, 2026
Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc....
Critical
Unreviewed
CVE-2026-16272
was published
Sep 9, 2026
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
Moderate
CVE-2026-16732
was published
for
fastify
(npm)
Sep 2, 2026
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
High
CVE-2026-55641
was published
for
9router
(npm)
Aug 28, 2026
CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
Moderate
CVE-2026-63220
was published
for
codeigniter4/framework
(Composer)
Aug 7, 2026
In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the ...
Moderate
Unreviewed
CVE-2026-50243
was published
Jul 22, 2026
Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
Moderate
CVE-2026-59897
was published
for
hono
(npm)
Jul 21, 2026
FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that...
High
Unreviewed
CVE-2026-64619
was published
Jul 20, 2026
Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler...
High
Unreviewed
CVE-2026-63770
was published
Jul 20, 2026
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows...
Critical
Unreviewed
CVE-2026-58122
was published
Jul 10, 2026
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over...
Moderate
Unreviewed
CVE-2026-59999
was published
Jul 8, 2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0...
Low
Unreviewed
CVE-2026-46466
was published
Jul 3, 2026
LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in...
Moderate
Unreviewed
CVE-2026-57942
was published
Jun 29, 2026
chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header
High
GHSA-rjr7-jggh-pgcp
was published
for
github.com/go-chi/chi/middleware
(Go)
Jun 25, 2026
An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active...
Critical
Unreviewed
CVE-2026-12249
was published
Jun 22, 2026
Use of Less Trusted Source vulnerability in Apache APISIX.
Attacker can take advantage of wolf...
Low
Unreviewed
CVE-2026-44046
was published
Jun 19, 2026
hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
Moderate
CVE-2026-54289
was published
for
hono
(npm)
Jun 16, 2026
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
Moderate
CVE-2026-48061
was published
for
litestar
(pip)
Jun 10, 2026
OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication...
Moderate
Unreviewed
CVE-2020-37248
was published
Jun 8, 2026
Caddy Defender trusted proxy client IP bypass
High
CVE-2026-46415
was published
for
pkg.jsn.cam/caddy-defender
(Go)
May 19, 2026
HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows...
High
Unreviewed
CVE-2026-43634
was published
May 19, 2026
In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted...
Moderate
Unreviewed
CVE-2026-40226
was published
Apr 10, 2026
Shynet before 0.14.0 allows Host header injection in the password reset flow.
Moderate
Unreviewed
CVE-2026-35507
was published
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API