GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
40 advisories
Filter by severity
Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg...
Moderate
Unreviewed
CVE-2018-16979
was published
May 14, 2022
HTTP header injection vulnerability in i-FILTER Ver.9.50R05 and earlier may allow remote...
Moderate
Unreviewed
CVE-2018-16181
was published
May 14, 2022
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in...
Moderate
Unreviewed
CVE-2016-5699
was published
May 14, 2022
Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Tomcat
Moderate
CVE-2014-0099
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
A vulnerability in the Cisco Email Security Appliance (ESA) could allow an unauthenticated,...
Moderate
Unreviewed
CVE-2017-12309
was published
May 13, 2022
Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0...
Moderate
Unreviewed
CVE-2017-17742
was published
May 13, 2022
Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
Moderate
CVE-2018-1067
was published
for
org.jboss.eap:wildfly-undertow
(Maven)
May 13, 2022
Moodle CRLF Injection Vulnerability in Calendar Component
Moderate
CVE-2011-4203
was published
for
moodle/moodle
(Composer)
May 13, 2022
CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x...
Moderate
Unreviewed
CVE-2007-5595
was published
May 1, 2022
HTTP Response Splitting in WSO2 transport-http
Moderate
CVE-2019-10797
was published
for
org.wso2.transport.http:org.wso2.transport.http.netty
(Maven)
Feb 9, 2022
HTTP Response Splitting (Early Hints) in Puma
Moderate
CVE-2020-5249
was published
for
puma
(RubyGems)
Mar 3, 2020
HTTP Response Splitting in Puma
Moderate
CVE-2020-5247
was published
for
puma
(RubyGems)
Feb 28, 2020
Limited header injection when using dynamic overrides with user input in RubyGems secure_headers
Moderate
CVE-2020-5216
was published
for
secure_headers
(RubyGems)
Jan 23, 2020
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') in Armeria
Moderate
GHSA-35fr-h7jr-hh86
was published
for
com.linecorp.armeria:armeria
(Maven)
Dec 6, 2019
Low severity vulnerability that affects com.linecorp.armeria:armeria
Moderate
CVE-2019-16771
was published
for
com.linecorp.armeria:armeria
(Maven)
Dec 5, 2019
ProTip!
Advisories are also available from the
GraphQL API