GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
911
pip
4,760
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
6,414 advisories
Filter by severity
Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
Critical
CVE-2026-40478
was published
for
org.thymeleaf:thymeleaf
(Maven)
Apr 15, 2026
Improper restriction of the scope of accessible objects in Thymeleaf expressions
Critical
CVE-2026-40477
was published
for
org.thymeleaf:thymeleaf
(Maven)
Apr 15, 2026
OpenRemote has XXE in Velbus Asset Import
High
CVE-2026-40882
was published
for
io.openremote:openremote-manager
(Maven)
Apr 15, 2026
Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache
Moderate
GHSA-xmj9-7625-f634
was published
for
dev.dsf:dsf-bpe-process-api-v2
(Maven)
Apr 15, 2026
Data Sharing Framework is Missing Session Timeout for OIDC Sessions
Moderate
GHSA-gj7p-595x-qwf5
was published
for
dev.dsf:dsf-bpe-server
(Maven)
Apr 15, 2026
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
High
CVE-2026-2332
was published
for
org.eclipse.jetty:jetty-http
(Maven)
Apr 14, 2026
XWiki's REST APIs can list all pages/spaces, leading to unavailability
Moderate
CVE-2026-40104
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Apr 14, 2026
XWiki has Reflected Cross-Site Scripting (XSS) in page history compare
Moderate
CVE-2026-40105
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Apr 14, 2026
Expression Injection in OpenRemote
Critical
CVE-2026-39842
was published
for
io.openremote:openremote-manager
(Maven)
Apr 14, 2026
Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code
Moderate
CVE-2026-33929
was published
for
org.apache.pdfbox:pdfbox-examples
(Maven)
Apr 14, 2026
AsyncHttpClient leaks authorization credentialsto untrusted domains on cross-origin redirects
Moderate
CVE-2026-40490
was published
for
org.asynchttpclient:async-http-client
(Maven)
Apr 14, 2026
Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
High
CVE-2026-5795
was published
for
org.eclipse.jetty.ee10:jetty-ee10-jaspi
(Maven)
Apr 14, 2026
Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix
High
CVE-2026-35582
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 13, 2026
Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata
Moderate
CVE-2026-35565
was published
for
org.apache.storm:storm-webapp
(Maven)
Apr 13, 2026
Apache Storm: Deserialization of Untrusted Data vulnerability
High
CVE-2026-35337
was published
for
org.apache.storm:storm-client
(Maven)
Apr 13, 2026
Warm-Flow has a SpEL Expression Injection in SpelHelper.parseExpression
Low
CVE-2026-6125
was published
for
org.dromara.warm:warm-flow-plugin-modes-sb
(Maven)
Apr 12, 2026
Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
Moderate
CVE-2026-34479
was published
for
org.apache.logging.log4j:log4j-1.2-api
(Maven)
Apr 10, 2026
Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
Moderate
CVE-2026-34481
was published
for
org.apache.logging.log4j:log4j-layout-template-json
(Maven)
Apr 10, 2026
Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration
Moderate
CVE-2026-34477
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Apr 10, 2026
Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
Moderate
CVE-2026-34478
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Apr 10, 2026
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
Moderate
CVE-2026-34480
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Apr 10, 2026
Apache ActiveMQ: Denial of Service via Out of Memory vulnerability
High
CVE-2026-39304
was published
for
org.apache.activemq:activemq-all
(Maven)
Apr 10, 2026
Spring Cloud Gateway's SSL bundle configuration silently bypassed
High
CVE-2026-22750
was published
for
org.springframework.cloud:spring-cloud-gateway
(Maven)
Apr 10, 2026
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
High
CVE-2026-34487
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
High
CVE-2026-34483
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
ProTip!
Advisories are also available from the
GraphQL API