GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,630
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,850
Pub
13
RubyGems
1,045
Rust
1,301
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,361 advisories
Filter by severity
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
High
CVE-2026-40171
was published
for
@jupyter-notebook/help-extension
(npm)
Apr 30, 2026
Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web...
Moderate
Unreviewed
CVE-2026-41226
was published
Apr 30, 2026
Admidio Sends SAML Response to Unvalidated Assertion Consumer Service URL from AuthnRequest
High
CVE-2026-41670
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
n8n has Open Redirect in MCP OAuth Consent Flow
Moderate
CVE-2026-42230
was published
for
n8n
(npm)
Apr 29, 2026
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not...
Moderate
Unreviewed
CVE-2026-42525
was published
Apr 29, 2026
An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows...
Moderate
Unreviewed
CVE-2026-30346
was published
Apr 27, 2026
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized...
Critical
Unreviewed
CVE-2026-33102
was published
Apr 24, 2026
Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass)
Moderate
GHSA-f3g8-9xv5-77gv
was published
for
@saltcorn/server
(npm)
Apr 16, 2026
Grafana Loki Path Traversal - CVE-2021-36156 Bypass
Moderate
CVE-2026-21726
was published
for
github.com/grafana/loki/v3
(Go)
Apr 15, 2026
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an...
Moderate
Unreviewed
CVE-2026-20060
was published
Apr 15, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint
Low
GHSA-7qx6-f23w-3w7f
was published
for
github.com/patrickhener/goshs
(Go)
Apr 14, 2026
@adonisjs/http-server has an Open Redirect vulnerability
Moderate
CVE-2026-40255
was published
for
@adonisjs/core
(npm)
Apr 14, 2026
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in...
Low
Unreviewed
CVE-2026-21741
was published
Apr 14, 2026
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an...
Moderate
Unreviewed
CVE-2026-34257
was published
Apr 14, 2026
Kimai has an Open Redirect via Unvalidated RelayState in SAML ACS Handler
Low
GHSA-3jp4-mhh4-gcgr
was published
for
kimai/kimai
(Composer)
Apr 14, 2026
The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in...
Moderate
Unreviewed
CVE-2026-6203
was published
Apr 14, 2026
next-intl has an open redirect vulnerability
Moderate
CVE-2026-40299
was published
for
next-intl
(npm)
Apr 10, 2026
An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be...
Moderate
Unreviewed
CVE-2026-22560
was published
Apr 10, 2026
Apache Tomcat has an Open Redirect vulnerability
Moderate
CVE-2026-25854
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects
High
GHSA-pg8g-f2hf-x82m
was published
for
openclaw
(npm)
Apr 9, 2026
•
withdrawn
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost...
Moderate
Unreviewed
CVE-2026-39484
was published
Apr 8, 2026
A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking...
High
Unreviewed
CVE-2026-23818
was published
Apr 7, 2026
An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a...
Moderate
Unreviewed
CVE-2025-61166
was published
Apr 6, 2026
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri
High
GHSA-x3f4-v83f-7wp2
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
Microsoft 7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash...
High
Unreviewed
CVE-2018-25245
was published
Apr 4, 2026
ProTip!
Advisories are also available from the
GraphQL API