GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,193
Erlang
25
GitHub Actions
39
Go
2,385
Maven
3,027
npm
3,078
NuGet
529
pip
2,897
Pub
5
RubyGems
442
Rust
905
Swift
20
Unreviewed advisories
All unreviewed
5,000+
16,334 advisories
Filter by severity
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
CVE-2026-40488
was published
for
openmage/magento-lts
(Composer)
Apr 21, 2026
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
High
CVE-2026-40161
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace
High
CVE-2026-39861
was published
for
@anthropic-ai/claude-code
(npm)
Apr 21, 2026
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
Low
CVE-2026-40264
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenBao's SQL Injection in PostgreSQL database secrets engine
Moderate
CVE-2026-39946
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
Low
CVE-2026-39396
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
Low
CVE-2026-39388
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
Neko has a Self-service Privilege Escalation for Authenticated Users
High
CVE-2026-39386
was published
for
github.com/m1k1o/neko/server
(Go)
Apr 21, 2026
nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
Moderate
CVE-2026-39378
was published
for
nbconvert
(pip)
Apr 21, 2026
nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
Moderate
CVE-2026-39377
was published
for
nbconvert
(pip)
Apr 21, 2026
Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths
High
CVE-2026-39320
was published
for
signalk-server
(npm)
Apr 21, 2026
October CMS: Editor Sub-Permission Bypass for Asset and Blueprint File Operations
Low
CVE-2026-29179
was published
for
october/system
(Composer)
Apr 21, 2026
October CMS: Reflected XSS via DataTable Form Widget
Low
CVE-2026-27937
was published
for
october/system
(Composer)
Apr 21, 2026
October CMS has Safe Mode Bypass via Twig Database Write Operations
Moderate
CVE-2026-26274
was published
for
october/october
(Composer)
Apr 21, 2026
October CMS has Safe Mode Bypass via CSS Preprocessor Compilers
Moderate
CVE-2026-26067
was published
for
october/system
(Composer)
Apr 21, 2026
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
Moderate
CVE-2026-25542
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Auth0 Next.js SDK has Improper Proxy Cache Lookup
Moderate
CVE-2026-40155
was published
for
@auth0/nextjs-auth0
(npm)
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Moderate
CVE-2026-40098
was published
for
openmage/magento-lts
(Composer)
Apr 21, 2026
Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
Moderate
CVE-2026-35588
was published
for
glances
(pip)
Apr 21, 2026
Glances has SSRF in IP Plugin via public_api leading to credential leakage
High
CVE-2026-35587
was published
for
glances
(pip)
Apr 21, 2026
OpenClaude: Sandbox Bypass via Early-Exit Logic Flaw Allows Path Traversal
High
CVE-2026-35570
was published
for
@gitlawb/openclaude
(npm)
Apr 21, 2026
Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
High
CVE-2026-34839
was published
for
Glances
(pip)
Apr 21, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints
High
CVE-2026-34403
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Apr 21, 2026
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
High
CVE-2026-33626
was published
for
lmdeploy
(pip)
Apr 21, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens
High
CVE-2026-33031
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Apr 21, 2026
ProTip!
Advisories are also available from the
GraphQL API