GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,850
Maven
5,000+
npm
4,485
NuGet
779
pip
4,238
Pub
12
RubyGems
975
Rust
1,093
Swift
48
Unreviewed advisories
All unreviewed
5,000+
355 advisories
Filter by severity
Bio-Formats performs unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing
Moderate
CVE-2026-22187
was published
for
ome:pom-bio-formats
(Maven)
Jan 7, 2026
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
Moderate
CVE-2025-13467
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Dec 19, 2025
Apache NiFi GetAsanaObject Processor has Remote Code Execution via Unsafe Deserialization
High
CVE-2025-66524
was published
for
org.apache.nifi:nifi-asana-processors
(Maven)
Dec 19, 2025
Apache HugeGraph-Server: RAFT and deserialization vulnerability
High
CVE-2025-26866
was published
for
org.apache.hugegraph:hg-pd-core
(Maven)
Dec 12, 2025
Duplicate Advisory: Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
Moderate
GHSA-93vm-mqpw-8wh3
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Nov 25, 2025
•
withdrawn
Apache Causeway vulnerable to deserialization in Java
Critical
CVE-2025-64408
was published
for
org.apache.causeway.commons:causeway-commons
(Maven)
Nov 19, 2025
Apache IoTDB: Deserialization of untrusted Data
Critical
CVE-2025-48459
was published
for
org.apache.iotdb:iotdb-confignode
(Maven)
Sep 24, 2025
H2O affected by a deserialization vulnerability
Critical
CVE-2025-6544
was published
for
ai.h2o:h2o-core
(Maven)
Sep 22, 2025
JasperReports has a Java deserialisation vulnerability
High
CVE-2025-10492
was published
for
net.sf.jasperreports:jasperreports
(Maven)
Sep 16, 2025
Apache Fory Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-59328
was published
for
org.apache.fory:fory-core
(Maven)
Sep 15, 2025
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
Moderate
CVE-2025-58782
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Sep 8, 2025
Apache Seata: Deserialization of untrusted Data in Apache Seata Server
High
CVE-2025-53606
was published
for
org.apache.seata:seata-serializer-fury
(Maven)
Aug 8, 2025
akka-cluster-metrics uses Java serialization for cluster metrics
Moderate
CVE-2025-53393
was published
for
com.typesafe.akka:akka-cluster-metrics_2.13
(Maven)
Jun 29, 2025
Apache Seata Vulnerable to Deserialization of Untrusted Data
Critical
CVE-2025-32897
was published
for
org.apache.seata:seata-config-core
(Maven)
Jun 28, 2025
PowSyBl Core allows deserialization of untrusted SparseMatrix data
High
CVE-2025-47771
was published
for
com.powsybl:powsybl-math
(Maven)
Jun 19, 2025
Apache Kafka Deserialization of Untrusted Data vulnerability
High
CVE-2025-27818
was published
for
org.apache.kafka:kafka_2.11
(Maven)
Jun 10, 2025
Apache Kafka Deserialization of Untrusted Data vulnerability
High
CVE-2025-27819
was published
for
org.apache.kafka:kafka_2.10
(Maven)
Jun 10, 2025
Apache InLong Deserialization of Untrusted Data Vulnerability
High
CVE-2025-27531
was published
for
org.apache.inlong:inlong-manager
(Maven)
Jun 6, 2025
Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read
Moderate
CVE-2025-27528
was published
for
org.apache.inlong:manager-pojo
(Maven)
May 28, 2025
Apache InLong: JDBC Vulnerability For URLEncode and backspace bypass
Moderate
CVE-2025-27526
was published
for
org.apache.inlong:manager-pojo
(Maven)
May 28, 2025
Apache InLong: JDBC Vulnerability during verification processing
High
CVE-2025-27522
was published
for
org.apache.inlong:manager-pojo
(Maven)
May 28, 2025
jooby-pac4j: deserialization of untrusted data
High
CVE-2025-31129
was published
for
io.jooby:jooby-pac4j
(Maven)
Apr 1, 2025
Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution
Critical
CVE-2025-30065
was published
for
org.apache.parquet:parquet-avro
(Maven)
Apr 1, 2025
aizuda snail-job Vulnerable to Deserialization via `nodeExpression` Argument
Moderate
CVE-2025-2622
was published
for
com.aizuda:snail-job
(Maven)
Mar 22, 2025
H2O Deserialization of Untrusted Data Vulnerability
Critical
CVE-2024-10553
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API