GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62Unreviewed advisories
All unreviewed
5,000+Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
1034,166 advisories
Filter by severity
Uh oh!
There was an error while loading. Please reload this page.
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
Moderate
CVE-2026-59817
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Member existence leak via magic link sign-in response
Moderate
CVE-2026-53947
was published
for
ghost
(npm)
Aug 4, 2026
XSS in Ghost's ActivityPub client
High
CVE-2026-53950
was published
for
@tryghost/activitypub
(npm)
Aug 4, 2026
Ghost: Session Fixation in Ghost Admin
Moderate
CVE-2026-70594
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Theme Upload Path Traversal
Moderate
CVE-2026-70593
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Database Backup Path Traversal
Moderate
CVE-2026-70592
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Server-Side Request Forgery in Image Fetching
Moderate
CVE-2026-70591
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Blind Password Hash Disclosure in Ghost Admin API
Moderate
CVE-2026-70590
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Mobiledoc image-size fetch SSRF
Moderate
CVE-2026-53946
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling
Moderate
CVE-2026-53945
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Private IP filtering bypass to make server-side requests to internal services
Moderate
CVE-2026-53944
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Archived Offers can be Redeemed
Moderate
CVE-2026-70589
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: File Upload Content-Type Spoofing
Moderate
CVE-2026-53948
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Cross-Site Scripting in Universal Import
Moderate
CVE-2026-70588
was published
for
ghost
(npm)
Aug 4, 2026
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
High
CVE-2026-70494
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Moderate
CVE-2026-70493
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
High
CVE-2026-70492
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
Moderate
CVE-2026-70491
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Moderate
CVE-2026-70490
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Moderate
CVE-2026-70489
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: DNS Rebinding SSRF Bypass
Moderate
CVE-2026-54020
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
Moderate
CVE-2026-70487
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Moderate
CVE-2026-70488
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
High
CVE-2026-70486
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
High
CVE-2026-70485
was published
for
open-webui
(pip)
Aug 4, 2026
ProTip!
Advisories are also available from the GraphQL API