GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
31 advisories
Filter by severity
A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the...
Low
Unreviewed
CVE-2026-18632
was published
Aug 3, 2026
Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote...
Moderate
Unreviewed
CVE-2026-18266
was published
Jul 29, 2026
Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend...
High
Unreviewed
CVE-2026-61461
was published
Jul 10, 2026
Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows...
Critical
Unreviewed
CVE-2026-41947
was published
May 18, 2026
Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview...
High
Unreviewed
CVE-2026-41949
was published
May 18, 2026
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated...
Critical
Unreviewed
CVE-2026-41948
was published
May 18, 2026
Dify before version 1.14.0 contains an authorization bypass vulnerability that allows...
Moderate
Unreviewed
CVE-2026-41950
was published
May 5, 2026
A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function...
Moderate
Unreviewed
CVE-2026-6619
was published
Apr 20, 2026
A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function...
Moderate
Unreviewed
CVE-2026-6618
was published
Apr 20, 2026
A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the...
Moderate
Unreviewed
CVE-2026-6617
was published
Apr 20, 2026
A vulnerability has been found in zhutoutoutousan worldquant-miner up to 1.0.9. The impacted...
Moderate
Unreviewed
CVE-2026-2711
was published
Feb 19, 2026
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker...
Critical
Unreviewed
CVE-2025-56157
was published
Dec 18, 2025
Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send...
High
Unreviewed
CVE-2025-63387
was published
Dec 18, 2025
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in...
Critical
Unreviewed
CVE-2025-63386
was published
Dec 18, 2025
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in...
Critical
Unreviewed
CVE-2025-63388
was published
Dec 18, 2025
In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user...
Moderate
Unreviewed
CVE-2025-11750
was published
Oct 22, 2025
Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component...
Moderate
Unreviewed
CVE-2025-56520
was published
Sep 30, 2025
langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node,...
Critical
Unreviewed
CVE-2025-3466
was published
Jul 7, 2025
An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting...
High
Unreviewed
CVE-2025-3467
was published
Jul 7, 2025
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component...
Moderate
Unreviewed
CVE-2025-29720
was published
Apr 14, 2025
A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including...
High
Unreviewed
CVE-2025-1796
was published
Mar 20, 2025
A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a...
High
Unreviewed
CVE-2025-0185
was published
Mar 20, 2025
A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10...
Moderate
Unreviewed
CVE-2025-0184
was published
Mar 20, 2025
In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password...
High
Unreviewed
CVE-2024-12776
was published
Mar 20, 2025
langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the...
Moderate
Unreviewed
CVE-2024-12775
was published
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API