GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
5,986 advisories
Filter by severity
CakePHP Authentication: Open redirect weakness via backslash bypass
Moderate
CVE-2026-55590
was published
for
cakephp/authentication
(Composer)
Jun 17, 2026
Filament: Disabled RichEditor field state can be used for XSS
High
CVE-2026-55409
was published
for
filament/forms
(Composer)
Jun 17, 2026
Laravel Framework: Temporary Signed URL Path Confusion
Moderate
GHSA-crmm-hgp2-wgrp
was published
for
laravel/framework
(Composer)
Jun 17, 2026
Laravel Framework: CRLF injection in default email rule
High
GHSA-5vg9-5847-vvmq
was published
for
laravel/framework
(Composer)
Jun 17, 2026
phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access
Moderate
GHSA-m557-wrgg-6rp4
was published
for
phpseclib/phpseclib
(Composer)
Jun 16, 2026
Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
Moderate
CVE-2026-48784
was published
for
symfony/routing
(Composer)
Jun 15, 2026
Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
Moderate
CVE-2026-48760
was published
for
symfony/html-sanitizer
(Composer)
Jun 15, 2026
Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
Moderate
CVE-2026-48747
was published
for
symfony/mailomat-mailer
(Composer)
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Moderate
CVE-2026-48736
was published
for
symfony/http-client
(Composer)
Jun 15, 2026
Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes
High
CVE-2026-48489
was published
for
symfony/security-http
(Composer)
Jun 15, 2026
Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes
Moderate
CVE-2026-48761
was published
for
symfony/html-sanitizer
(Composer)
Jun 15, 2026
TYPO3 CMS has Broken Access Control in its Form Framework
High
CVE-2026-11607
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in the Recycler Module
Moderate
CVE-2026-47349
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities
Moderate
CVE-2026-47347
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS: Destructive Actions on File Mount Folders
High
CVE-2026-47343
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 HTML Sanitizer allows Cross-site Scripting
Moderate
CVE-2026-47345
was published
for
typo3/html-sanitizer
(Composer)
Jun 12, 2026
TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework
High
CVE-2026-49741
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its DataHandler
Moderate
CVE-2026-47350
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its Form Framework
High
CVE-2026-47346
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its Media Module
High
CVE-2026-49742
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Insecure Deserialization via Core API
Moderate
CVE-2026-49740
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its File Abstraction Layer
Low
CVE-2026-49738
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in Backend API
Moderate
CVE-2026-47352
was published
for
typo3/cms-backend
(Composer)
Jun 12, 2026
TYPO3 CMS: Broken Access Control in Media Module
Moderate
CVE-2026-47351
was published
for
typo3/cms-backend
(Composer)
Jun 12, 2026
TYPO3 CMS has Cross-Site Scripting in Indexed Search
Moderate
CVE-2026-47348
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
ProTip!
Advisories are also available from the
GraphQL API