GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,248
Erlang
31
GitHub Actions
21
Go
2,014
Maven
5,000+
npm
3,721
NuGet
662
pip
3,393
Pub
11
RubyGems
890
Rust
852
Swift
36
Unreviewed advisories
All unreviewed
5,000+
62 advisories
Filter by severity
CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote...
Moderate
Unreviewed
CVE-2016-6484
was published
May 14, 2022
Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a...
Moderate
Unreviewed
CVE-2015-9096
was published
May 14, 2022
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed...
High
Unreviewed
CVE-2017-15400
was published
May 14, 2022
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4...
Moderate
Unreviewed
CVE-2014-2017
was published
May 14, 2022
Improper Neutralization of CRLF Sequences in Wildfly Undertow
Moderate
CVE-2016-4993
was published
for
org.wildfly:wildfly-undertow
(Maven)
May 17, 2022
CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.
Moderate
Unreviewed
CVE-2017-14037
was published
May 17, 2022
CRLF injection vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband...
Moderate
Unreviewed
CVE-2014-9564
was published
May 17, 2022
CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows...
Moderate
Unreviewed
CVE-2017-6508
was published
May 17, 2022
CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote...
Moderate
Unreviewed
CVE-2017-5868
was published
May 17, 2022
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a CRLF...
Moderate
Unreviewed
CVE-2017-8788
was published
May 17, 2022
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a home/seos...
Moderate
Unreviewed
CVE-2017-8791
was published
May 17, 2022
HTTP header injection vulnerability in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2...
Moderate
Unreviewed
CVE-2017-2111
was published
May 17, 2022
bottle.py vulnerable to CRLF Injection
High
CVE-2016-9964
was published
for
bottle
(pip)
May 17, 2022
An issue was discovered in Weaver e-cology 9.0. There is a CRLF Injection vulnerability via the ...
Moderate
Unreviewed
CVE-2019-10272
was published
May 24, 2022
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11...
High
Unreviewed
CVE-2018-19585
was published
May 24, 2022
Incorrect implementation in Content Security Policy in Google Chrome prior to 67.0.3396.79...
Moderate
Unreviewed
CVE-2018-6148
was published
May 24, 2022
cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923).
High
Unreviewed
CVE-2016-10803
was published
May 24, 2022
A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA)...
Moderate
Unreviewed
CVE-2020-3561
was published
May 24, 2022
Duplicate Advisory: Improper Neutralization of CRLF Sequences in dio
High
GHSA-jwpw-q68h-r678
was published
for
dio
(Pub)
May 24, 2022
•
withdrawn
undici before v5.8.0 vulnerable to CRLF injection in request headers
Moderate
CVE-2022-31150
was published
for
undici
(npm)
Jul 21, 2022
undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect
Low
CVE-2022-31151
was published
for
undici
(npm)
Jul 21, 2022
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
Moderate
CVE-2022-35948
was published
for
undici
(npm)
Aug 18, 2022
CRLF Injection in Nodejs ‘undici’ via host
Moderate
CVE-2023-23936
was published
for
undici
(npm)
Feb 16, 2023
dio vulnerable to CRLF injection with HTTP method string
High
CVE-2021-31402
was published
for
dio
(Pub)
Mar 21, 2023
Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when...
High
Unreviewed
CVE-2023-26130
was published
May 30, 2023
ProTip!
Advisories are also available from the
GraphQL API