GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            335 advisories
        Filter by severity
        
      
      
    
                    
                      Byaidu PDFMathTranslate vulnerable to open redirect
                    
                      
  Low
                    
                
                      
                        CVE-2025-50736
                      
                      was published
                        for
                        
                          pdf2zh
                        
                        (pip)
                      Oct 30, 2025 
                    
                  
                    
                      Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
                    
                      
  Low
                    
                
                      
                        GHSA-cf57-c578-7jvv
                      
                      was published
                        for
                        
                          github.com/TecharoHQ/anubis
                        
                        (Go)
                      Oct 30, 2025 
                    
                  
                    
                      ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection
                    
                      
  High
                    
                
                      
                        CVE-2025-64101
                      
                      was published
                        for
                        
                          github.com/zitadel/zitadel/v2
                        
                        (Go)
                      Oct 29, 2025 
                    
                  
                    
                      PrivateBin is missing HTML sanitization of attached filename in file size hint
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62796
                      
                      was published
                        for
                        
                          privatebin/privatebin
                        
                        (Composer)
                      Oct 28, 2025 
                    
                  
                    
                      Liferay Portal Vulnerable to Open Redirect via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameter
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62253
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.layout.admin.web
                        
                        (Maven)
                      Oct 27, 2025 
                    
                  
                    
                      vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
                    
                      
  High
                    
                
                      
                        CVE-2025-6242
                      
                      was published
                        for
                        
                          vllm
                        
                        (pip)
                      Oct 7, 2025 
                    
                  
                    
                      Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62595
                      
                      was published
                        for
                        
                          koa
                        
                        (npm)
                      Oct 21, 2025 
                    
                  
                    
                      reflex-dev/reflex has an Open Redirect vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-62379
                      
                      was published
                        for
                        
                          reflex
                        
                        (pip)
                      Oct 15, 2025 
                    
                  
                    
                      chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
                    
                      
  Moderate
                    
                
                      
                        GHSA-vrw8-fxc6-2r93
                      
                      was published
                        for
                        
                          github.com/go-chi/chi/v5
                        
                        (Go)
                      Jun 20, 2025 
                    
                  
                    
                      WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-1440
                      
                      was published
                        for
                        
                          org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util
                        
                        (Maven)
                      Jun 2, 2025 
                    
                  
                    
                      lobe-chat has an Open Redirect
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59426
                      
                      was published
                        for
                        
                          @lobehub/chat
                        
                        (npm)
                      Sep 24, 2025 
                    
                  
                    
                      Mattermost Open Redirect vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-9084
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Sep 15, 2025 
                    
                  
                    
                      Mattermost Open Redirect vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-9072
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Sep 15, 2025 
                    
                  
                    
                      Liferay Portal's System, Instance and Site Settings are vulnerable to Open Redirect
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-43795
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.configuration.admin.web
                        
                        (Maven)
                      Sep 12, 2025 
                    
                  
                    
                      TYPO3 CMS has an open‑redirect vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59013
                      
                      was published
                        for
                        
                          typo3/cms-core
                        
                        (Composer)
                      Sep 9, 2025 
                    
                  
                    
                      Google Sign-In for Rails allowed redirect to protocol-relative URI
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-58067
                      
                      was published
                        for
                        
                          google_sign_in
                        
                        (RubyGems)
                      Aug 29, 2025 
                    
                  
                    
                      Google Sign-In for Rails allowed redirects to malformed URLs
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-57821
                      
                      was published
                        for
                        
                          google_sign_in
                        
                        (RubyGems)
                      Aug 27, 2025 
                    
                  
                    
                      Liferay Portal allows open redirect in /c/portal/edit_info_item parameter redirect
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-43767
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.info.impl
                        
                        (Maven)
                      Aug 23, 2025 
                    
                  
                    
                      @astrojs/node's trailing slash handling causes open redirect issue
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-55207
                      
                      was published
                        for
                        
                          @astrojs/node
                        
                        (npm)
                      Aug 15, 2025 
                    
                  
                    
                      svg-sanitizer Bypasses Attribute Sanitization
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-55166
                      
                      was published
                        for
                        
                          enshrined/svg-sanitize
                        
                        (Composer)
                      Aug 12, 2025 
                    
                  
                    
                      Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-35029
                      
                      was published
                        for
                        
                          com.liferay.portal:release.dxp.bom
                        
                        (Maven)
                      Jun 15, 2023 
                    
                  
                    
                      Apache Tomcat Open Redirect vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-41080
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-core
                        
                        (Maven)
                      Aug 25, 2023 
                    
                  
                    
                      Astros's duplicate trailing slash feature leads to an open redirection security issue
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54793
                      
                      was published
                        for
                        
                          astro
                        
                        (npm)
                      Aug 7, 2025 
                    
                  
                    
                      Koa Open Redirect via Referrer Header (User-Controlled)
                    
                      
  Low
                    
                
                      
                        CVE-2025-8129
                      
                      was published
                        for
                        
                          koa
                        
                        (npm)
                      Jul 29, 2025 
                    
                  
                    
                      Duplicate Advisory: Koa Open Redirect via Referrer Header (User-Controlled)
                    
                      
  Low
                    
                
                      
                        GHSA-mvw6-62qv-vmqf
                      
                      was published
                        for
                        
                          koa
                        
                        (npm)
                      Jul 25, 2025 
                        •
                        
                          withdrawn
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API