GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,912
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
36,725 advisories
Filter by severity
fast-jwt: Verifier cache accepts expired JWTs without iat.
Moderate
CVE-2026-107719
was published
for
fast-jwt
(npm)
Oct 8, 2026
Hazelcast allows arbitrary member memory access by low-privileged client
Critical
CVE-2026-107726
was published
for
com.hazelcast:hazelcast
(Maven)
Oct 8, 2026
Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry
Moderate
CVE-2026-107716
was published
for
banks
(pip)
Oct 8, 2026
Banks: User-controlled prompt input can be parsed as privileged chat messages
Moderate
CVE-2026-107717
was published
for
banks
(pip)
Oct 8, 2026
Indico: Incomplete Server-Side Request Forgery (SSRF) check
Moderate
CVE-2026-107394
was published
for
indico
(pip)
Oct 8, 2026
Indico: Missing access check in legacy session export API
Moderate
CVE-2026-107395
was published
for
indico
(pip)
Oct 8, 2026
Indico: Cross-Site-Scripting in minutes editor
Moderate
CVE-2026-107397
was published
for
indico
(pip)
Oct 8, 2026
Indico: Cross-Site-Scripting in link fields
Moderate
CVE-2026-107396
was published
for
indico
(pip)
Oct 8, 2026
Hazelcast has an authorization bypass in IMap Predicates API
High
CVE-2026-107725
was published
for
com.hazelcast:hazelcast
(Maven)
Oct 8, 2026
AdonisJS: Unencoded route parameters can produce open redirects
Moderate
CVE-2026-107718
was published
for
@adonisjs/http-server
(npm)
Oct 8, 2026
Mechanize sends credential headers to another origin after a meta refresh
Moderate
CVE-2026-107399
was published
for
mechanize
(RubyGems)
Oct 8, 2026
Mechanize sends credential headers to another host after an HTTP redirect
Moderate
CVE-2026-107715
was published
for
mechanize
(RubyGems)
Oct 8, 2026
fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set
High
CVE-2026-107720
was published
for
fast-jwt
(npm)
Oct 8, 2026
fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion
Critical
CVE-2026-107722
was published
for
fast-jwt
(npm)
Oct 8, 2026
fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)
Moderate
CVE-2026-107721
was published
for
fast-jwt
(npm)
Oct 8, 2026
fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
High
CVE-2026-107723
was published
for
fast-jwt
(npm)
Oct 8, 2026
fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery
High
CVE-2026-107724
was published
for
fast-jwt
(npm)
Oct 8, 2026
PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
High
CVE-2026-61426
was published
for
praisonai
(npm)
Oct 8, 2026
PraisonAI: Platform member PATCH routes allow owner resource rewrites and project lead reassignment delete bypass
High
CVE-2026-61442
was published
for
praisonai-platform
(pip)
Oct 8, 2026
PraisonAI: Shell command allowlist bypass via find -exec built-in action
High
CVE-2026-61434
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls
Critical
CVE-2026-61445
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
High
CVE-2026-61427
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: Platform members can rewrite shared labels and owner issue labels without owner/admin authorization
Moderate
CVE-2026-61440
was published
for
praisonai-platform
(pip)
Oct 8, 2026
PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend
High
CVE-2026-60085
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
High
CVE-2026-60091
was published
for
praisonai
(pip)
Oct 8, 2026
ProTip!
Advisories are also available from the
GraphQL API