GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
76 advisories
Filter by severity
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion
Moderate
CVE-2026-11748
was published
for
com.linecorp.centraldogma:centraldogma-server-auth-shiro
(Maven)
Sep 11, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-80055
was published
Sep 9, 2026
The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating...
Moderate
Unreviewed
CVE-2026-78579
was published
Sep 8, 2026
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')...
Moderate
Unreviewed
CVE-2026-81205
was published
Sep 2, 2026
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')...
High
Unreviewed
CVE-2026-75020
was published
Aug 27, 2026
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')...
High
Unreviewed
CVE-2026-19271
was published
Aug 26, 2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76373
was published
Aug 20, 2026
A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP)...
Moderate
Unreviewed
CVE-2026-74241
was published
Aug 15, 2026
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Moderate
CVE-2026-53658
was published
for
github.com/hyperledger/fabric-ca
(Go)
Aug 14, 2026
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user...
Moderate
Unreviewed
CVE-2026-16071
was published
Aug 5, 2026
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
Moderate
Unreviewed
CVE-2026-59652
was published
Aug 3, 2026
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP...
High
Unreviewed
CVE-2026-11770
was published
Jul 31, 2026
LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished...
Moderate
Unreviewed
CVE-2026-44617
was published
Jul 30, 2026
LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP...
Moderate
Unreviewed
CVE-2026-44616
was published
Jul 30, 2026
A security flaw combining LDAP filter injection and improper authorization checks was found in...
High
Unreviewed
CVE-2026-58222
was published
Jul 30, 2026
Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability
High
CVE-2026-47303
was published
for
Microsoft.AspNetCore.Authentication.Negotiate
(NuGet)
Jul 21, 2026
Improper neutralization of special elements used in an LDAP query ('LDAP injection')...
High
Unreviewed
CVE-2026-4256
was published
Jul 9, 2026
Improper neutralization of special elements used in an LDAP query ('LDAP injection')...
High
Unreviewed
CVE-2026-13696
was published
Jul 7, 2026
OpenAM Authentication Bypass via MSISDN LDAP Injection
High
CVE-2026-46619
was published
for
org.openidentityplatform.openam:openam-auth-msisdn
(Maven)
Jun 26, 2026
Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building...
Low
Unreviewed
CVE-2026-57288
was published
Jun 24, 2026
OpenBao: LDAPi ldaputil (wrong escape func)
Moderate
CVE-2026-55770
was published
for
github.com/openbao/openbao
(Go)
Jun 19, 2026
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
High
CVE-2026-49268
was published
for
org.apache.shiro:shiro-core
(Maven)
Jun 17, 2026
Yamcs Vulnerable to LDAP Injection in LdapAuthModule
Moderate
CVE-2026-42568
was published
for
org.yamcs:yamcs-core
(Maven)
May 26, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
Moderate
CVE-2026-46745
was published
for
apache-airflow-providers-fab
(pip)
May 26, 2026
Apache CXF has an LDAP injection vulnerability
Critical
CVE-2026-44930
was published
for
org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap
(Maven)
May 26, 2026
ProTip!
Advisories are also available from the
GraphQL API