GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,318
Erlang
31
GitHub Actions
21
Go
2,074
Maven
5,000+
npm
3,746
NuGet
674
pip
3,434
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
220 advisories
Filter by severity
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a...
Moderate
Unreviewed
CVE-2019-0197
was published
May 24, 2022
AeroAdmin 4.1 uses an insecure protocol (HTTP) to perform software updates. An attacker can...
High
Unreviewed
CVE-2017-8894
was published
May 17, 2022
An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS...
High
Unreviewed
CVE-2017-15643
was published
May 17, 2022
HPE has identified a remote HOST header attack vulnerability in HPE CentralView Fraud Risk...
Moderate
Unreviewed
CVE-2018-7068
was published
May 14, 2022
There are multiple HTTP smuggling and cache poisoning issues when clients making malicious...
Moderate
Unreviewed
CVE-2018-8004
was published
May 14, 2022
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP...
Critical
Unreviewed
CVE-2015-5740
was published
May 14, 2022
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP...
Critical
Unreviewed
CVE-2015-5739
was published
May 14, 2022
Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP
High
CVE-2017-7561
was published
for
org.jboss.resteas:resteasy-jaxrs
(Maven)
May 13, 2022
Undertow Request Smuggling vulnerability
High
CVE-2017-12165
was published
for
io.undertow:undertow-core
(Maven)
May 13, 2022
Undertow vulnerable to Request Smuggling
Moderate
CVE-2017-7559
was published
for
io.undertow:undertow-core
(Maven)
May 13, 2022
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can...
High
Unreviewed
CVE-2018-12116
was published
May 13, 2022
Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability...
Critical
Unreviewed
CVE-2016-10711
was published
May 13, 2022
An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung...
High
Unreviewed
CVE-2018-3907
was published
May 13, 2022
An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung...
High
Unreviewed
CVE-2018-3908
was published
May 13, 2022
An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung...
High
Unreviewed
CVE-2018-3909
was published
May 13, 2022
An exploitable vulnerability exists the safe browsing function of the CUJO Smart Firewall,...
High
Unreviewed
CVE-2018-4030
was published
May 13, 2022
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2...
High
Unreviewed
CVE-2017-2850
was published
May 13, 2022
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used...
Moderate
Unreviewed
CVE-2006-6276
was published
May 1, 2022
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy,...
Moderate
Unreviewed
CVE-2005-2088
was published
May 1, 2022
Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application...
Moderate
Unreviewed
CVE-2005-2089
was published
May 1, 2022
A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift...
Moderate
Unreviewed
CVE-2022-0552
was published
Apr 12, 2022
Inconsistent Interpretation of HTTP Requests in twisted.web
Critical
CVE-2022-24801
was published
for
twisted
(pip)
Apr 4, 2022
Puma vulnerable to HTTP Request Smuggling
Critical
CVE-2022-24790
was published
for
puma
(RubyGems)
Mar 30, 2022
BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4...
High
Unreviewed
CVE-2021-25220
was published
Mar 24, 2022
Insufficient Protection against HTTP Request Smuggling in mitmproxy
Critical
CVE-2022-24766
was published
for
mitmproxy
(pip)
Mar 22, 2022
ProTip!
Advisories are also available from the
GraphQL API