GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,849
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
6,374 advisories
Filter by severity
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
High
CVE-2026-85740
was published
for
lightrag-hku
(pip)
Sep 22, 2026
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
Critical
CVE-2026-85734
was published
for
lightrag-hku
(pip)
Sep 22, 2026
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function
Moderate
CVE-2026-85725
was published
for
lightrag-hku
(pip)
Sep 22, 2026
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
Moderate
CVE-2026-85709
was published
for
lightrag-hku
(pip)
Sep 22, 2026
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
Moderate
CVE-2026-83805
was published
for
nautobot
(pip)
Sep 22, 2026
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text
Moderate
CVE-2026-83801
was published
for
nautobot
(pip)
Sep 22, 2026
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation
Moderate
CVE-2026-77528
was published
for
autobahn
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
High
CVE-2026-77258
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions
Moderate
CVE-2026-77250
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
Moderate
CVE-2026-77249
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
High
CVE-2026-77247
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token
Critical
CVE-2026-77244
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: SSRF Protection Bypass
High
CVE-2026-77274
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)
High
CVE-2026-77271
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
mcp-atlassian has an incomplete SSRF remediation
High
CVE-2026-77267
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler
Moderate
CVE-2026-77272
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
High
CVE-2026-77262
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Insecure File Permissions on OAuth Token Storage
Moderate
CVE-2026-77268
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
High
CVE-2026-77259
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches
High
CVE-2026-77261
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
Moderate
CVE-2026-77270
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
Moderate
CVE-2026-77265
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call
Moderate
CVE-2026-77266
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)
Moderate
CVE-2026-77269
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)
High
CVE-2026-77260
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
ProTip!
Advisories are also available from the
GraphQL API