GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,880
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
36,435 advisories
Filter by severity
Payload didn't enforce field-level password update restrictions
High
CVE-2026-105855
was published
for
payload
(npm)
Oct 6, 2026
Payload: ReDoS in Multipart Content-Type Validation
High
CVE-2026-105854
was published
for
payload
(npm)
Oct 6, 2026
Payload vulnerable to API key disclosure through ordinary document reads
High
CVE-2026-105849
was published
for
payload
(npm)
Oct 6, 2026
Payload Ecommerce has an order confirmation validation issue
High
CVE-2026-105850
was published
for
@payloadcms/plugin-ecommerce
(npm)
Oct 6, 2026
Payload relationship-query authorization bypass
Moderate
CVE-2026-105852
was published
for
payload
(npm)
Oct 6, 2026
Payload: Token refresh and password reset responses may expose restricted user fields
High
CVE-2026-105853
was published
for
payload
(npm)
Oct 6, 2026
Payload: Field access control bypass on auth collections
Critical
CVE-2026-105851
was published
for
payload
(npm)
Oct 6, 2026
Payload: Insufficient Access Control in Stripe REST Proxy
Moderate
CVE-2026-105848
was published
for
@payloadcms/plugin-stripe
(npm)
Oct 6, 2026
Payload: Improper access control for MCP API keys
High
CVE-2026-105806
was published
for
@payloadcms/plugin-mcp
(npm)
Oct 6, 2026
Payload: Prototype pollution in Payload Import Export plugin
Critical
CVE-2026-105844
was published
for
@payloadcms/plugin-import-export
(npm)
Oct 6, 2026
Payload: SQL Injection in SQLite and Postgres
Critical
CVE-2026-105845
was published
for
payload
(npm)
Oct 6, 2026
Payload: Untrusted redirect URL parameter exploit
Moderate
CVE-2026-105846
was published
for
@payloadcms/next
(npm)
Oct 6, 2026
Payload: Polymorphic join queries could disclose hidden fields
High
CVE-2026-105847
was published
for
payload
(npm)
Oct 6, 2026
Payload: Password hashes use insufficient PBKDF2 iterations
Moderate
CVE-2026-105804
was published
for
payload
(npm)
Oct 6, 2026
Payload: Sort queries could expose protected field information
Moderate
CVE-2026-105805
was published
for
payload
(npm)
Oct 6, 2026
Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests
Low
CVE-2026-105795
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Oct 6, 2026
Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators
High
CVE-2026-105796
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Oct 6, 2026
MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
High
CVE-2026-104850
was published
for
@modelcontextprotocol/client
(npm)
Oct 6, 2026
i18next-http-backend incomplete URL validation permits SSRF
Low
CVE-2026-105800
was published
for
i18next-http-backend
(npm)
Oct 6, 2026
MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL
Critical
CVE-2026-105794
was published
for
Microsoft.Native.Quic.MsQuic.OpenSSL
(NuGet)
Oct 6, 2026
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation
High
CVE-2026-105801
was published
for
openapi-python-client
(pip)
Oct 6, 2026
LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values
Low
CVE-2026-105799
was published
for
@langchain/redis
(npm)
Oct 6, 2026
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration
High
CVE-2026-26287
was published
for
github.com/external-secrets/external-secrets
(Go)
Oct 6, 2026
Vyper: Memory corruption using function calls within tuples / nested calls
Moderate
GHSA-2r3x-4mrv-mcxf
was published
for
vyper
(pip)
Oct 6, 2026
Vyper: Call stack corruption when passing complex type containing non-base type members as argument
Moderate
GHSA-4v7v-gqf9-ww2g
was published
for
vyper
(pip)
Oct 6, 2026
ProTip!
Advisories are also available from the
GraphQL API