GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,782
Erlang
36
GitHub Actions
29
Go
2,347
Maven
5,000+
npm
3,976
NuGet
720
pip
3,774
Pub
12
RubyGems
923
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
245 advisories
Filter by severity
chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
Moderate
GHSA-vrw8-fxc6-2r93
was published
for
github.com/go-chi/chi/v5
(Go)
Jun 20, 2025
urllib3 does not control redirects in browsers and Node.js
Moderate
CVE-2025-50182
was published
for
urllib3
(pip)
Jun 18, 2025
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
Moderate
CVE-2025-50181
was published
for
urllib3
(pip)
Jun 18, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
Moderate
CVE-2025-5256
was published
for
mautic/core
(Composer)
May 28, 2025
Flask-AppBuilder open redirect vulnerability using HTTP host injection
Moderate
CVE-2025-32962
was published
for
flask-appbuilder
(pip)
May 16, 2025
@cloudflare/workers-oauth-provider missing validation of redirect_uri on authorize endpoint
Moderate
CVE-2025-4143
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
Duplicate Advisory: @cloudflare/workers-oauth-provider missing validation of redirect_uri on authorize endpoint
Moderate
GHSA-7cp4-jw97-3rc2
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
•
withdrawn
org.xwiki.platform:xwiki-platform-wysiwyg-api Open Redirect vulnerability
Moderate
CVE-2025-32970
was published
for
org.xwiki.platform:xwiki-platform-wysiwyg-api
(Maven)
Apr 29, 2025
Apache Druid vulnerable to Server-Side Request Forgery, Cross-site Scripting, Open Redirect
Moderate
CVE-2025-27888
was published
for
org.apache.druid:druid
(Maven)
Mar 20, 2025
Gradio Vulnerable to Open Redirect
Moderate
CVE-2024-8021
was published
for
gradio
(pip)
Mar 20, 2025
BentoML Open Redirect vulnerability
Moderate
GHSA-564p-rx2q-4c8v
was published
for
bentoml
(pip)
Mar 20, 2025
FastChat open redirect vulnerability
Moderate
CVE-2024-10908
was published
for
fschat
(pip)
Mar 20, 2025
Jenkins Open Redirect vulnerability
Moderate
CVE-2025-27625
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 6, 2025
CodeChecker open redirect when URL contains multiple slashes after the product name
Moderate
CVE-2025-1300
was published
for
codechecker
(pip)
Mar 3, 2025
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
Moderate
CVE-2025-27143
was published
for
better-auth
(npm)
Feb 24, 2025
TYPO3 Potential Open Redirect via Parsing Differences
Moderate
CVE-2024-55892
was published
for
typo3/cms-core
(Composer)
Jan 14, 2025
BunkerWeb has Open Redirect Vulnerability in Loading Page
Moderate
CVE-2024-53264
was published
for
github.com/bunkerity/bunkerweb
(Go)
Dec 2, 2024
Traefik's X-Forwarded-Prefix Header still allows for Open Redirect
Moderate
CVE-2024-52003
was published
for
github.com/traefik/traefik/v2
(Go)
Dec 2, 2024
Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect')
Moderate
GHSA-wcx9-ccpj-hx3c
was published
for
github.com/coder/coder/v2
(Go)
Oct 28, 2024
Keycloak has Vulnerable Redirect URI Validation Results in Open Redirect
Moderate
CVE-2024-8883
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 14, 2024
Eclipse Glassfish improperly handles http parameters
Moderate
CVE-2024-9329
was published
for
org.glassfish.main.admin:rest-service
(Maven)
Sep 30, 2024
Eclipse Glassfish URL redirection vulnerability
Moderate
CVE-2024-8646
was published
for
org.glassfish.main.web:web-core
(Maven)
Sep 11, 2024
Keycloak Open Redirect vulnerability
Moderate
CVE-2024-7260
was published
for
org.keycloak:keycloak-core
(Maven)
Sep 9, 2024
WebOb's location header normalization during redirect leads to open redirect
Moderate
CVE-2024-42353
was published
for
webob
(pip)
Aug 14, 2024
lorawan-stack Open Redirect vulnerability
Moderate
CVE-2023-26494
was published
for
go.thethings.network/lorawan-stack/v3
(Go)
Aug 5, 2024
ProTip!
Advisories are also available from the
GraphQL API