GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,373
Erlang
33
GitHub Actions
22
Go
2,135
Maven
5,000+
npm
3,797
NuGet
687
pip
3,478
Pub
12
RubyGems
896
Rust
897
Swift
38
Unreviewed advisories
All unreviewed
5,000+
224 advisories
Filter by severity
A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to...
Moderate
Unreviewed
CVE-2023-51219
was published
Jun 3, 2024
X-Forwarded-For header allows brute-forcing autoblocked IP addresses
Critical
CVE-2023-29141
was published
for
mediawiki/core
(Composer)
Mar 31, 2023
Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows...
High
Unreviewed
CVE-2024-23452
was published
Feb 8, 2024
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services...
Moderate
Unreviewed
CVE-2024-21281
was published
Oct 15, 2024
Undertow incorrectly parses cookies
High
CVE-2023-4639
was published
for
io.undertow:undertow-core
(Maven)
Nov 17, 2024
io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
High
CVE-2024-12397
was published
for
io.quarkus.http:quarkus-http-core
(Maven)
Dec 12, 2024
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access...
Moderate
Unreviewed
CVE-2025-0752
was published
Jan 28, 2025
LavaLite vulnerable to web cache poisoning
Critical
CVE-2023-27238
was published
for
lavalite/cms
(Composer)
May 12, 2023
Waitress has request processing race condition in HTTP pipelining with invalid first request
Critical
CVE-2024-49768
was published
for
waitress
(pip)
Oct 29, 2024
Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP
High
CVE-2017-7561
was published
for
org.jboss.resteasy:resteasy-jaxrs
(Maven)
May 13, 2022
Request smuggling leading to endpoint restriction bypass in Gunicorn
High
CVE-2024-1135
was published
for
gunicorn
(pip)
Apr 16, 2024
In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to...
Critical
Unreviewed
CVE-2023-29476
was published
Dec 14, 2024
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in...
Moderate
Unreviewed
CVE-2024-53008
was published
Nov 28, 2024
Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
Moderate
CVE-2024-9666
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 25, 2024
Duplicate Advisory: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
Moderate
GHSA-pcx7-8hxg-j823
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 25, 2024
•
withdrawn
In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request...
Moderate
Unreviewed
CVE-2024-34535
was published
Oct 3, 2024
Inconsistent Interpretation of HTTP Requests in twisted.web
Critical
CVE-2022-24801
was published
for
twisted
(pip)
Apr 4, 2022
Improper Input Validation in Twisted
Critical
CVE-2020-10108
was published
for
Twisted
(pip)
Mar 31, 2020
HTTP Request Smuggling in Twisted
Critical
CVE-2020-10109
was published
for
Twisted
(pip)
Mar 31, 2020
aiohttp allows request smuggling due to incorrect parsing of chunk extensions
Moderate
CVE-2024-52304
was published
for
aiohttp
(pip)
Nov 18, 2024
HTTP Request Smuggling in waitress
High
CVE-2022-24761
was published
for
waitress
(pip)
Mar 18, 2022
HTTP Request Smuggling in Waitress: Invalid whitespace characters in headers (Follow-up)
Moderate
CVE-2019-16789
was published
for
waitress
(pip)
Jan 6, 2020
HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress
Moderate
CVE-2019-16786
was published
for
waitress
(pip)
Dec 20, 2019
HTTP Request Smuggling: LF vs CRLF handling in Waitress
Moderate
CVE-2019-16785
was published
for
waitress
(pip)
Dec 20, 2019
twisted.web has disordered HTTP pipeline response
Moderate
CVE-2023-46137
was published
for
twisted
(pip)
Oct 25, 2023
ProTip!
Advisories are also available from the
GraphQL API