GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
952 advisories
Filter by severity
URL Redirection to Untrusted Site ('Open Redirect') in Products.isurlinportal
Moderate
CVE-2021-32806
was published
for
Products.isurlinportal
(pip)
Aug 5, 2021
URIjs Vulnerable to Hostname spoofing via backslashes in URL
Moderate
CVE-2021-3647
was published
for
urijs
(npm)
Jul 19, 2021
Open Redirect in github.com/AndrewBurian/powermux
Moderate
CVE-2021-32721
was published
for
github.com/AndrewBurian/powermux
(Go)
Jul 1, 2021
Open redirect in Flask-Unchained
Moderate
CVE-2021-23393
was published
for
Flask-Unchained
(pip)
Jun 15, 2021
Open Redirect in trailing-slash
Moderate
CVE-2021-23387
was published
for
trailing-slash
(npm)
Jun 8, 2021
Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy
Low
CVE-2021-21291
was published
for
github.com/oauth2-proxy/oauth2-proxy
(Go)
May 25, 2021
OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses
Moderate
CVE-2020-15233
was published
for
github.com/ory/fosite
(Go)
May 24, 2021
Redirect URL matching ignores character casing
Moderate
CVE-2020-15234
was published
for
github.com/ory/fosite
(Go)
May 24, 2021
Open redirect in direct_mail
Moderate
CVE-2020-12699
was published
for
directmailteam/direct-mail
(Composer)
May 24, 2021
JWT leak via Open Redirect in Programmatic access
Moderate
CVE-2021-29651
was published
for
github.com/pomerium/pomerium
(Go)
May 21, 2021
pomerium_signature is not verified in middleware in github.com/pomerium/pomerium
Moderate
CVE-2021-29652
was published
for
github.com/pomerium/pomerium
(Go)
May 21, 2021
gopkg.in/macaron.v1 Open Redirect vulnerability
Moderate
CVE-2020-12666
was published
for
gopkg.in/macaron.v1
(Go)
May 18, 2021
Open Redirect in Flask-Security-Too
Low
CVE-2021-32618
was published
for
Flask-Security-Too
(pip)
May 17, 2021
Open Redirect in Liferay Portal
High
CVE-2020-24554
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 7, 2021
Possible Open Redirect Vulnerability in Action Pack
Moderate
CVE-2021-22903
was published
for
actionpack
(RubyGems)
May 5, 2021
Open redirect via transitional IPv6 addresses on dual-stack networks
Moderate
CVE-2021-21392
was published
for
matrix-synapse
(pip)
Apr 13, 2021
OMERO webclient does not validate URL redirects on login or switching group.
Moderate
CVE-2021-21377
was published
for
omero-web
(pip)
Mar 23, 2021
Open Redirection in Login Handling
Moderate
CVE-2021-21338
was published
for
typo3/cms
(Composer)
Mar 23, 2021
URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService
Low
CVE-2021-21337
was published
for
Products.PluggableAuthService
(pip)
Mar 8, 2021
Actionpack Open Redirect Vulnerability
Moderate
CVE-2021-22881
was published
for
actionpack
(RubyGems)
Mar 2, 2021
Open redirects on some federation and push requests
Low
CVE-2021-21273
was published
for
matrix-synapse
(pip)
Feb 26, 2021
ProTip!
Advisories are also available from the
GraphQL API