| route-pattern | /advisories(.:format) |
| route-controller | global_advisories |
| route-action | index |
| fetch-nonce | v2:56effb1c-6bd3-6b8b-cebf-9806915e803f |
| current-catalog-service-hash | b5fafa2158e952dddc485a80b5ade8af1f45dec1b0b35bad86be148d2e4340e0 |
| request-id | DA90:37ADE8:26EBAC9:335D75C:696B2340 |
| html-safe-nonce | 50eb75335c71d873ae65a08f40e24e59113992f0856f5991173220fe2f7b5578 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJEQTkwOjM3QURFODoyNkVCQUM5OjMzNUQ3NUM6Njk2QjIzNDAiLCJ2aXNpdG9yX2lkIjoiMjY2NzA2ODg0MzExNTYxOTEzNiIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 91e9ab0aa64eec5789e48d7e0893433f95c8d5e40c74226dbdc5ed82ef6376da |
| github-keyboard-shortcuts | copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/advisories |
| twitter:image | https://github.githubassets.com/assets/advisory-database-index-a58a6165227c.png |
| twitter:card | summary_large_image |
| og:image | https://github.githubassets.com/assets/advisory-database-index-a58a6165227c.png |
| og:image:alt | A database of software vulnerabilities, using data from maintainer-submitted advisories and from other vulnerability databases. |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 5f99f7c1d70f01da5b93e5ca90303359738944d8ab470e396496262c66e60b8d |
| turbo-cache-control | no-preview |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 82560a55c6b2054555076f46e683151ee28a19bc |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
| Skip to content | https://patch-diff.githubusercontent.com/advisories#start-of-content |
|
| https://patch-diff.githubusercontent.com/ |
|
Sign in
| https://patch-diff.githubusercontent.com/login?return_to=https%3A%2F%2Fgithub.com%2Fadvisories |
| GitHub CopilotWrite better code with AI | https://github.com/features/copilot |
| GitHub SparkBuild and deploy intelligent apps | https://github.com/features/spark |
| GitHub ModelsManage and compare prompts | https://github.com/features/models |
| MCP RegistryNewIntegrate external tools | https://github.com/mcp |
| ActionsAutomate any workflow | https://github.com/features/actions |
| CodespacesInstant dev environments | https://github.com/features/codespaces |
| IssuesPlan and track work | https://github.com/features/issues |
| Code ReviewManage code changes | https://github.com/features/code-review |
| GitHub Advanced SecurityFind and fix vulnerabilities | https://github.com/security/advanced-security |
| Code securitySecure your code as you build | https://github.com/security/advanced-security/code-security |
| Secret protectionStop leaks before they start | https://github.com/security/advanced-security/secret-protection |
| Why GitHub | https://github.com/why-github |
| Documentation | https://docs.github.com |
| Blog | https://github.blog |
| Changelog | https://github.blog/changelog |
| Marketplace | https://github.com/marketplace |
| View all features | https://github.com/features |
| Enterprises | https://github.com/enterprise |
| Small and medium teams | https://github.com/team |
| Startups | https://github.com/enterprise/startups |
| Nonprofits | https://github.com/solutions/industry/nonprofits |
| App Modernization | https://github.com/solutions/use-case/app-modernization |
| DevSecOps | https://github.com/solutions/use-case/devsecops |
| DevOps | https://github.com/solutions/use-case/devops |
| CI/CD | https://github.com/solutions/use-case/ci-cd |
| View all use cases | https://github.com/solutions/use-case |
| Healthcare | https://github.com/solutions/industry/healthcare |
| Financial services | https://github.com/solutions/industry/financial-services |
| Manufacturing | https://github.com/solutions/industry/manufacturing |
| Government | https://github.com/solutions/industry/government |
| View all industries | https://github.com/solutions/industry |
| View all solutions | https://github.com/solutions |
| AI | https://github.com/resources/articles?topic=ai |
| Software Development | https://github.com/resources/articles?topic=software-development |
| DevOps | https://github.com/resources/articles?topic=devops |
| Security | https://github.com/resources/articles?topic=security |
| View all topics | https://github.com/resources/articles |
| Customer stories | https://github.com/customer-stories |
| Events & webinars | https://github.com/resources/events |
| Ebooks & reports | https://github.com/resources/whitepapers |
| Business insights | https://github.com/solutions/executive-insights |
| GitHub Skills | https://skills.github.com |
| Documentation | https://docs.github.com |
| Customer support | https://support.github.com |
| Community forum | https://github.com/orgs/community/discussions |
| Trust center | https://github.com/trust-center |
| Partners | https://github.com/partners |
| GitHub SponsorsFund open source developers | https://github.com/sponsors |
| Security Lab | https://securitylab.github.com |
| Maintainer Community | https://maintainers.github.com |
| Accelerator | https://github.com/accelerator |
| Archive Program | https://archiveprogram.github.com |
| Topics | https://github.com/topics |
| Trending | https://github.com/trending |
| Collections | https://github.com/collections |
| Enterprise platformAI-powered developer platform | https://github.com/enterprise |
| GitHub Advanced SecurityEnterprise-grade security features | https://github.com/security/advanced-security |
| Copilot for BusinessEnterprise-grade AI features | https://github.com/features/copilot/copilot-business |
| Premium SupportEnterprise-grade 24/7 support | https://github.com/premium-support |
| Pricing | https://github.com/pricing |
| Search syntax tips | https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax |
| documentation | https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax |
|
Sign in
| https://patch-diff.githubusercontent.com/login?return_to=https%3A%2F%2Fgithub.com%2Fadvisories |
|
Sign up
| https://patch-diff.githubusercontent.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2Fadvisories&source=header |
| Reload | https://patch-diff.githubusercontent.com/advisories |
| Reload | https://patch-diff.githubusercontent.com/advisories |
| Reload | https://patch-diff.githubusercontent.com/advisories |
| All reviewed
25,464
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed |
| Composer
5,137
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Acomposer |
| Erlang
40
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Aerlang |
| GitHub Actions
38
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Aactions |
| Go
2,831
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Ago |
| Maven
6,209
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Amaven |
| npm
4,462
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Anpm |
| NuGet
775
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Anuget |
| pip
4,226
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Apip |
| Pub
12
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Apub |
| RubyGems
972
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Arubygems |
| Rust
1,093
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Arust |
| Swift
47
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Aswift |
| All unreviewed
285,914
| https://patch-diff.githubusercontent.com/advisories?query=type%3Aunreviewed |
|
CC-BY-4.0 License | https://docs.github.com/en/github/site-policy/github-additional-product-terms#12-advisory-database |
|
Language support | https://docs.github.com/code-security/security-advisories/working-with-global-security-advisories-from-the-github-advisory-database/about-the-github-advisory-database#github-reviewed-advisories |
|
About GitHub Advisory Database | https://docs.github.com/code-security/security-advisories/working-with-global-security-advisories-from-the-github-advisory-database/about-the-github-advisory-database |
|
All reviewed
5,000+
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed |
|
Composer
5,000+
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Acomposer |
|
Erlang
40
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Aerlang |
|
GitHub Actions
38
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Aactions |
|
Go
2,831
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Ago |
|
Maven
5,000+
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Amaven |
|
npm
4,462
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Anpm |
|
NuGet
775
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Anuget |
|
pip
4,226
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Apip |
|
Pub
12
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Apub |
|
RubyGems
972
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Arubygems |
|
Rust
1,093
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Arust |
|
Swift
47
| https://patch-diff.githubusercontent.com/advisories?query=type%3Areviewed+ecosystem%3Aswift |
|
All unreviewed
5,000+
| https://patch-diff.githubusercontent.com/advisories?query=type%3Aunreviewed |
|
All severities
| https://patch-diff.githubusercontent.com/advisories |
|
Low
| https://patch-diff.githubusercontent.com/advisories?query=severity%3Alow |
|
Moderate
| https://patch-diff.githubusercontent.com/advisories?query=severity%3Amoderate |
|
High
| https://patch-diff.githubusercontent.com/advisories?query=severity%3Ahigh |
|
Critical
| https://patch-diff.githubusercontent.com/advisories?query=severity%3Acritical |
| Please reload this page | https://patch-diff.githubusercontent.com/advisories |
|
Newest
| https://patch-diff.githubusercontent.com/advisories |
|
Oldest
| https://patch-diff.githubusercontent.com/advisories?query=sort%3Apublished-asc |
|
Recently updated
| https://patch-diff.githubusercontent.com/advisories?query=sort%3Aupdated-desc |
|
Least recently updated
| https://patch-diff.githubusercontent.com/advisories?query=sort%3Aupdated-asc |
|
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
| https://patch-diff.githubusercontent.com/advisories/GHSA-8qq5-rm4j-mr97 |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3AJvr2022 |
|
REC in MCPJam inspector due to HTTP Endpoint exposes
| https://patch-diff.githubusercontent.com/advisories/GHSA-232v-j27c-5pp6 |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Ac2an1 |
|
GraphQL Modules has a Race Condition issue
| https://patch-diff.githubusercontent.com/advisories/GHSA-53wg-r69p-v3r7 |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3ADuckThom |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Aenisdenjo |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Aardatan |
|
Veramo is Vulnerable to SQL Injection in Veramo Data Store ORM
| https://patch-diff.githubusercontent.com/advisories/GHSA-38cw-85xc-xr9x |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Arekter0 |
|
Skipper is vulnerable to arbitrary code execution through lua filters
| https://patch-diff.githubusercontent.com/advisories/GHSA-cc8m-98fm-rc9g |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Ab0b0haha |
|
svelte is vulnerable to XSS with textarea bind:value
| https://patch-diff.githubusercontent.com/advisories/GHSA-gw32-9rmw-qwww |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Acoyotte508 |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3AConduitry |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Abenmccann |
|
CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting
| https://patch-diff.githubusercontent.com/advisories/GHSA-qh8m-9qxx-53m5 |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Amarkstory |
|
Crawl4AI is Vulnerable to Remote Code Execution in Docker API via Hooks Parameter
| https://patch-diff.githubusercontent.com/advisories/GHSA-5882-5rx9-xgxp |
|
Crawl4AI Has Local File Inclusion in Docker API via file:// URLs
| https://patch-diff.githubusercontent.com/advisories/GHSA-vx9w-5cx4-9796 |
|
SiYuan Has a Stored Cross-Site Scripting (XSS) Vulnerability via Unrestricted SVG File Upload
| https://patch-diff.githubusercontent.com/advisories/GHSA-pcjq-j3mq-jv5j |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Ajaroslaw-wawiorko |
|
Active Job - Object injection security vulnerability
| https://patch-diff.githubusercontent.com/advisories/GHSA-mpwp-4h2m-765c |
|
ActiveRecord-JDBC-Adapter (AR-JDBC) lib/arjdbc/jdbc/adapter.rb sql.gsub() Function SQL Injection
| https://patch-diff.githubusercontent.com/advisories/GHSA-5qw5-wf2q-f538 |
|
pyasn1 has a DoS vulnerability in decoder
| https://patch-diff.githubusercontent.com/advisories/GHSA-63vm-454h-vhhq |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Atsigouris007 |
|
Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
| https://patch-diff.githubusercontent.com/advisories/GHSA-mmwx-79f6-67jg |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3AZee99y |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Anijel |
|
Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
| https://patch-diff.githubusercontent.com/advisories/GHSA-c336-7962-wfj2 |
|
Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
| https://patch-diff.githubusercontent.com/advisories/GHSA-m3c4-prhw-mrx6 |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3ASharokhAtaie |
|
Deno node:crypto doesn't finalize cipher
| https://patch-diff.githubusercontent.com/advisories/GHSA-5379-f5hf-w38v |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Adavidebombelli |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Avdata1 |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3AreallyTG |
|
RustFS's RPC signature verification logs shared secret
| https://patch-diff.githubusercontent.com/advisories/GHSA-333v-68xh-8mmq |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Arand-tech |
|
Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability
| https://patch-diff.githubusercontent.com/advisories/GHSA-fccg-7w3p-w66f |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Aaugustocesarperin |
|
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
| https://patch-diff.githubusercontent.com/advisories/GHSA-3qmm-r55x-hpxx |
|
Apache Airflow proxy credentials for various providers might leak in task logs
| https://patch-diff.githubusercontent.com/advisories/GHSA-7c2f-r6gc-h92h |
|
Mattermost is vulnerable to DoS due to infinite re-renders on API errors
| https://patch-diff.githubusercontent.com/advisories/GHSA-mx8m-v8qm-xwr8 |
|
Mattermost is vulnerable to CPU exhaustion via crafted HTTP request
| https://patch-diff.githubusercontent.com/advisories/GHSA-9r42-rhw3-2222 |
|
PlantUML is vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams
| https://patch-diff.githubusercontent.com/advisories/GHSA-hrvf-g648-rf3m |
|
Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stall
| https://patch-diff.githubusercontent.com/advisories/GHSA-cwjm-3f7h-9hwq |
| https://patch-diff.githubusercontent.com/advisories?query=credit%3Apavelkohout396 |
| 400 | https://patch-diff.githubusercontent.com/advisories?page=400 |
| Next | https://patch-diff.githubusercontent.com/advisories?page=2 |
| 2 | https://patch-diff.githubusercontent.com/advisories?page=2 |
| 3 | https://patch-diff.githubusercontent.com/advisories?page=3 |
| 4 | https://patch-diff.githubusercontent.com/advisories?page=4 |
| 5 | https://patch-diff.githubusercontent.com/advisories?page=5 |
| 399 | https://patch-diff.githubusercontent.com/advisories?page=399 |
| 400 | https://patch-diff.githubusercontent.com/advisories?page=400 |
| Next | https://patch-diff.githubusercontent.com/advisories?page=2 |
| GraphQL API | https://docs.github.com/graphql/reference/queries#securityadvisories |
|
CC-BY-4.0 License | https://docs.github.com/en/github/site-policy/github-additional-product-terms#12-advisory-database |
|
Language support | https://docs.github.com/code-security/security-advisories/working-with-global-security-advisories-from-the-github-advisory-database/about-the-github-advisory-database#github-reviewed-advisories |
|
About GitHub Advisory Database | https://docs.github.com/code-security/security-advisories/working-with-global-security-advisories-from-the-github-advisory-database/about-the-github-advisory-database |
|
| https://github.com |
| Terms | https://docs.github.com/site-policy/github-terms/github-terms-of-service |
| Privacy | https://docs.github.com/site-policy/privacy-policies/github-privacy-statement |
| Security | https://github.com/security |
| Status | https://www.githubstatus.com/ |
| Community | https://github.community/ |
| Docs | https://docs.github.com/ |
| Contact | https://support.github.com?tags=dotcom-footer |