GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
229 advisories
Filter by severity
froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl...
High
Unreviewed
CVE-2026-100717
was published
Sep 26, 2026
A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm...
High
Unreviewed
CVE-2026-91839
was published
Sep 25, 2026
A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to...
High
Unreviewed
CVE-2026-91840
was published
Sep 25, 2026
A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged...
High
Unreviewed
CVE-2026-91841
was published
Sep 25, 2026
zbateson/mail-mime-parser has CRLF header injection via attachment filename
High
CVE-2026-61815
was published
for
zbateson/mail-mime-parser
(Composer)
Sep 24, 2026
Improper neutralization of newlines in filter values in the monitoring host and service list APIs...
Moderate
Unreviewed
CVE-2026-90990
was published
Sep 22, 2026
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent...
Moderate
Unreviewed
CVE-2026-94057
was published
Sep 20, 2026
Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE...
High
Unreviewed
CVE-2026-93576
was published
Sep 18, 2026
An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in...
High
Unreviewed
CVE-2026-40530
was published
Sep 18, 2026
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in...
Low
Unreviewed
CVE-2026-13666
was published
Sep 18, 2026
A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function...
Moderate
Unreviewed
CVE-2026-90819
was published
Sep 14, 2026
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs,...
Critical
Unreviewed
CVE-2026-90937
was published
Sep 14, 2026
Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add()...
High
Unreviewed
CVE-2026-90767
was published
Sep 13, 2026
The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user...
Moderate
Unreviewed
CVE-2026-86813
was published
Sep 11, 2026
Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections
Critical
CVE-2026-84372
was published
for
predis/predis
(Composer)
Sep 8, 2026
CakePHP: SmtpTransport vulnerable to CRLF header injection
High
CVE-2026-77634
was published
for
cakephp/cakephp
(Composer)
Sep 8, 2026
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
Moderate
CVE-2026-84379
was published
for
httpx2
(pip)
Sep 8, 2026
The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from...
Moderate
Unreviewed
CVE-2026-19862
was published
Sep 6, 2026
Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an...
Critical
Unreviewed
CVE-2026-75925
was published
Sep 5, 2026
Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport...
Moderate
Unreviewed
CVE-2026-82853
was published
Aug 31, 2026
Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope...
Critical
Unreviewed
CVE-2026-82854
was published
Aug 31, 2026
Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list...
Moderate
Unreviewed
CVE-2026-82661
was published
Aug 31, 2026
Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands...
Moderate
Unreviewed
CVE-2026-33606
was published
Aug 28, 2026
Spring MVC applications using the functional web framework are vulnerable to stream corruption...
Critical
Unreviewed
CVE-2026-59313
was published
Aug 27, 2026
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent...
Critical
Unreviewed
CVE-2026-47890
was published
Aug 27, 2026
ProTip!
Advisories are also available from the
GraphQL API