GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
2,891
Erlang
24
GitHub Actions
39
Go
2,240
Maven
2,698
npm
2,899
NuGet
500
pip
2,728
Pub
5
RubyGems
364
Rust
889
Swift
19
Unreviewed advisories
All unreviewed
5,000+
24 advisories
Filter by severity
Ecto missing `is_nil` requirement
Critical
CVE-2017-20166
was published
for
ecto
(Erlang)
Apr 12, 2022
Phoenix before 1.6.14 mishandles check_origin wildcarding
High
CVE-2022-42975
was published
for
phoenix
(Erlang)
Oct 17, 2022
phoenix_html allows Cross-site Scripting in HEEx class attributes
Moderate
CVE-2021-46871
was published
for
phoenix_html
(Erlang)
Jan 10, 2023
Duplicate Advisory: Ecto lacks a protection mechanism
Critical
GHSA-4r2f-6fm9-2qgh
was published
for
ecto
(Erlang)
Jan 10, 2023
•
withdrawn
Livebook Desktop's protocol handler can be exploited to execute arbitrary command on Windows
High
CVE-2023-35174
was published
for
livebook
(Erlang)
Jun 21, 2023
MTProto proxy remote code execution vulnerability
High
CVE-2023-45312
was published
for
mtproto_proxy
(Erlang)
Oct 10, 2023
erlang-jose vulnerable to denial of service via large p2c value
Moderate
CVE-2023-50966
was published
for
jose
(Erlang)
Mar 19, 2024
Server-side Request Forgery (SSRF) in hackney
Low
CVE-2025-1211
was published
for
hackney
(Erlang)
Feb 11, 2025
Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`
Moderate
CVE-2025-25202
was published
for
ash_authentication
(Erlang)
Feb 11, 2025
ash_authentication has email link auto-click account confirmation vulnerability
Moderate
CVE-2025-32782
was published
for
ash_authentication
(Erlang)
Apr 14, 2025
Hackney fails to properly release HTTP connections to the pool
Low
CVE-2025-3864
was published
for
hackney
(Erlang)
May 28, 2025
ash_authentication_phoenix has Insufficient Session Expiration
Low
CVE-2025-4754
was published
for
ash_authentication_phoenix
(Erlang)
Jun 17, 2025
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
High
CVE-2025-48042
was published
for
ash
(Erlang)
Sep 15, 2025
Ash has authorization bypass when bypass policy condition evaluates to true
High
CVE-2025-48044
was published
for
ash
(Erlang)
Oct 17, 2025
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
hex_core has Unsafe Deserialization of Erlang Terms
Low
CVE-2026-21619
was published
for
hex_core
(Erlang)
Mar 1, 2026
Permissive List of Allowed Inputs in ewe
Moderate
CVE-2026-32881
was published
for
ewe
(Erlang)
Mar 16, 2026
Loop with Unreachable Exit Condition ('Infinite Loop') in ewe
High
CVE-2026-32873
was published
for
ewe
(Erlang)
Mar 16, 2026
esaml XXE vulnerability allows local file disclosure and SSRF via crafted SAML messages
Moderate
CVE-2026-28809
was published
for
esaml
(Erlang)
Mar 23, 2026
elixir-nodejs has Cross-User Data Leakage or Information Disclosure due to Worker Protocol Race Condition
High
CVE-2026-33872
was published
for
nodejs
(Erlang)
Mar 26, 2026
Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
High
CVE-2026-34593
was published
for
ash
(Erlang)
Apr 1, 2026
ewe Has Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Request/Response Splitting)
Moderate
CVE-2026-34715
was published
for
ewe
(Erlang)
Apr 1, 2026
wisp has Allocation of Resources Without Limits or Throttling
High
CVE-2026-32145
was published
for
wisp
(Erlang)
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API