GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,049
pip
5,000+
Pub
13
RubyGems
1,128
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
Critical
CVE-2026-56266
was published
for
crawl4ai
(pip)
Jun 16, 2026
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
Critical
CVE-2026-53753
was published
for
crawl4ai
(pip)
Jun 16, 2026
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
High
CVE-2026-44496
was published
for
axios
(npm)
Jun 4, 2026
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
High
CVE-2026-44495
was published
for
axios
(npm)
May 29, 2026
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
High
CVE-2026-44494
was published
for
axios
(npm)
May 29, 2026
OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation
Moderate
CVE-2026-45292
was published
for
io.opentelemetry:opentelemetry-api
(Maven)
May 14, 2026
Netty Redis Codec Encoder has a CRLF Injection Issue
Moderate
CVE-2026-42586
was published
for
io.netty:netty-codec-redis
(Maven)
May 7, 2026
Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)
High
CVE-2026-42579
was published
for
io.netty:netty-codec-dns
(Maven)
May 7, 2026
Netty has HTTP Header Injection via HttpProxyHandler Disabled Validation (Incomplete Fix CVE-2025-67735)
Low
CVE-2026-42578
was published
for
io.netty:netty-handler-proxy
(Maven)
May 7, 2026
Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
Moderate
CVE-2026-42042
was published
for
axios
(npm)
May 5, 2026
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Moderate
CVE-2026-42041
was published
for
axios
(npm)
May 5, 2026
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
Moderate
CVE-2026-42044
was published
for
axios
(npm)
May 5, 2026
Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
Low
CVE-2026-42040
was published
for
axios
(npm)
May 5, 2026
HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover
High
CVE-2026-22704
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jan 13, 2026
ProTip!
Advisories are also available from the
GraphQL API