GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,826
Erlang
36
GitHub Actions
32
Go
2,426
Maven
5,000+
npm
4,058
NuGet
723
pip
3,848
Pub
12
RubyGems
934
Rust
1,006
Swift
38
Unreviewed advisories
All unreviewed
5,000+
75 advisories
Filter by severity
Keycloak-services SMTP Inject Vulnerability
Moderate
CVE-2025-8419
was published
for
org.keycloak:keycloak-services
(Maven)
Aug 6, 2025
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi...
High
Unreviewed
CVE-2025-6175
was published
Jul 29, 2025
CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before...
Moderate
Unreviewed
CVE-2025-0293
was published
Jul 8, 2025
An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF...
Moderate
Unreviewed
CVE-2024-51981
was published
Jun 26, 2025
A vulnerability was found in Ritlabs TinyWeb Server 1.94. It has been classified as problematic....
Moderate
Unreviewed
CVE-2024-5193
was published
May 22, 2024
SQL injection vulnerability in AES Multimedia's Gestnet v1.07. This vulnerability allows an...
Critical
Unreviewed
CVE-2025-40671
was published
May 26, 2025
CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote...
Moderate
Unreviewed
CVE-2017-5868
was published
May 17, 2022
HTTP header injection vulnerability in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2...
Moderate
Unreviewed
CVE-2017-2111
was published
May 17, 2022
A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high...
High
Unreviewed
CVE-2023-38551
was published
May 31, 2024
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported...
Moderate
Unreviewed
CVE-2024-50405
was published
Mar 7, 2025
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported...
High
Unreviewed
CVE-2024-53693
was published
Mar 7, 2025
Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
Moderate
CVE-2025-27111
was published
for
rack
(RubyGems)
Mar 4, 2025
Possible Log Injection in Rack::CommonLogger
Moderate
CVE-2025-25184
was published
for
rack
(RubyGems)
Feb 12, 2025
The Umbraco Heartcore headless client library uses a vulnerable Refit dependency package
Low
GHSA-mgr7-5782-6jh9
was published
for
Umbraco.Headless.Client.Net
(NuGet)
Jan 13, 2025
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported...
High
Unreviewed
CVE-2024-48868
was published
Dec 6, 2024
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported...
Moderate
Unreviewed
CVE-2024-48867
was published
Dec 6, 2024
Improper Neutralization of CRLF Sequences in urllib3 library for Python
Moderate
CVE-2019-11236
was published
for
urllib3
(pip)
May 13, 2022
bottle.py vulnerable to CRLF Injection
High
CVE-2016-9964
was published
for
bottle
(pip)
May 17, 2022
CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes
Critical
CVE-2024-51501
was published
for
Refit
(NuGet)
Nov 4, 2024
Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when...
High
Unreviewed
CVE-2023-26130
was published
May 30, 2023
CRLF Injection in RestSharp's `RestRequest.AddHeader` method
Moderate
CVE-2024-45302
was published
for
RestSharp
(NuGet)
Aug 29, 2024
Kallithea CRLF injection vulnerability
High
CVE-2015-5285
was published
for
kallithea
(pip)
May 13, 2022
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
CVE-2018-1000164
was published
for
gunicorn
(pip)
Jul 12, 2018
ProTip!
Advisories are also available from the
GraphQL API