GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
22 advisories
Filter by severity
league/commonmark: Denial of service via deeply nested XML output
Moderate
GHSA-mj63-m3rc-8ppr
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via colliding heading slugs
High
GHSA-mh25-x5hq-wrqp
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via duplicate footnote definitions
High
GHSA-jfm3-95jq-q3rf
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via adjacent inline attribute blocks
High
GHSA-g2gp-3wwq-f4ph
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
High
CVE-2026-71488
was published
for
league/commonmark
(Composer)
Aug 6, 2026
Guzzle: Noncanonical cookie domain keeps subdomain scope
Moderate
CVE-2026-69245
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
Moderate
CVE-2026-59882
was published
for
guzzlehttp/psr7
(Composer)
Jul 21, 2026
Guzzle: URI fragments disclosed in redirect Referer headers
Moderate
CVE-2026-67354
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Guzzle: Host-only cookie scope is not preserved
Moderate
CVE-2026-67355
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Guzzle: Unbounded response cookies risk denial of service
Moderate
CVE-2026-67353
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
Moderate
CVE-2026-59883
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Guzzle: Proxy-Authorization headers can be sent to origin servers
Moderate
CVE-2026-67339
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
Moderate
CVE-2026-55568
was published
for
guzzlehttp/guzzle
(Composer)
Jun 19, 2026
guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator
Moderate
CVE-2026-53723
was published
for
guzzlehttp/guzzle-services
(Composer)
Jun 11, 2026
Chrome PHP is missing encoding in `CssSelector`
Moderate
CVE-2025-48883
was published
for
chrome-php/chrome
(Composer)
May 28, 2025
Slow String Operations via MultiPart Requests in Event-Driven Functions
Moderate
CVE-2024-29186
was published
for
bref/bref
(Composer)
Mar 22, 2024
HTTP Multiline Header Termination
High
CVE-2023-29530
was published
for
laminas/laminas-diactoros
(Composer)
Apr 24, 2023
Improper header name validation in guzzlehttp/psr7
Moderate
CVE-2023-29197
was published
for
guzzlehttp/psr7
(Composer)
Apr 19, 2023
Insecure header validation in slim/psr7
Moderate
CVE-2023-30536
was published
for
slim/psr7
(Composer)
Apr 18, 2023
Failure to strip the Cookie header on change in host or HTTP downgrade
High
CVE-2022-31042
was published
for
guzzlehttp/guzzle
(Composer)
Jun 9, 2022
Fix failure to strip Authorization header on HTTP downgrade
High
CVE-2022-31043
was published
for
guzzlehttp/guzzle
(Composer)
Jun 9, 2022
Improper Input Validation in guzzlehttp/psr7
Moderate
CVE-2022-24775
was published
for
guzzlehttp/psr7
(Composer)
Mar 25, 2022
ProTip!
Advisories are also available from the
GraphQL API