Package added to advisory
What a record said when it was published, what it says now, and the commit that changed it.
1,695 advisory changes · newest first · grouped by day
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Advisory, Which advisory was edited, by its GHSA id. | Package, The package the advisory names, and the registry it comes from. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|
| Tue 1 Sep 2026· 2 changes | ||||
| 2026-09-01published 2026-06-16 | GHSA-5r4w-85f3-pw66CVE-2026-48491 | high | not named as affected when the advisory was published, now names github.com/traefik/traefik/v2 | Time to revision 77 days |
| 2026-09-01published 2026-06-16 | GHSA-5r4w-85f3-pw66CVE-2026-48491 | high | not named as affected when the advisory was published, now names github.com/traefik/traefik/v3 | Time to revision 77 days |
| Mon 31 Aug 2026· 1 change | ||||
| 2026-08-31published 2026-05-12 | GHSA-r29c-68gh-xp6xCVE-2026-41293 | critical | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 111 days |
| Fri 14 Aug 2026· 2 changes | ||||
| 2026-08-14published 2026-02-19 | GHSA-p6jf-79j3-33f3CVE-2025-13590 | critical | not named as affected when the advisory was published, now names org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1 | Time to revision 176 days |
| 2026-08-14published 2026-04-29 | GHSA-w22p-4x9f-486vCVE-2026-42523 | critical | not named as affected when the advisory was published, now names com.coravy.hudson.plugins.github:github | Time to revision 107 days |
| Tue 4 Aug 2026· 2 changes | ||||
| 2026-08-04published 2026-06-03 | GHSA-2j2x-hqr9-3h42CVE-2026-40181 | moderate | not named as affected when the advisory was published, now names @remix-run/router | Time to revision 62 days |
| 2026-08-04published 2026-07-21 | GHSA-w5pg-649r-p6ggCVE-2026-58439 | high | not named as affected when the advisory was published, now names code.gitea.io/gitea | Time to revision 13 days |
| Fri 31 Jul 2026· 1 change | ||||
| 2026-07-31published 2026-07-21 | GHSA-m4p7-r5rc-7g4jCVE-2026-59884 | high | not named as affected when the advisory was published, now names pyasn1 | Time to revision 10 days |
| Thu 30 Jul 2026· 2 changes | ||||
| 2026-07-30published 2025-05-13 | GHSA-qqcr-9jfc-35c4CVE-2024-56526 | high | not named as affected when the advisory was published, now names oxid-esales/oxideshop-metapackage-ce | Time to revision 443 days |
| 2026-07-30published 2025-05-13 | GHSA-qqcr-9jfc-35c4CVE-2024-56526 | high | not named as affected when the advisory was published, now names oxid-esales/smarty-component | Time to revision 443 days |
| Fri 24 Jul 2026· 1 change | ||||
| 2026-07-24published 2026-05-06 | GHSA-rwm7-x88c-3g2pCVE-2026-42577 | high | not named as affected when the advisory was published, now names io.netty:netty-transport-classes-epoll | Time to revision 79 days |
| Tue 21 Jul 2026· 3 changes | ||||
| 2026-07-21published 2026-05-07 | GHSA-g924-cjx7-2rjwCVE-2026-42597 | moderate | not named as affected when the advisory was published, now names github.com/gotenberg/gotenberg/v7 | Time to revision 76 days |
| 2026-07-21published 2026-04-14 | GHSA-2hx3-vp6r-mg3fCVE-2026-41134 | high | not named as affected when the advisory was published, now names microsoft.openapi.kiota | Time to revision 98 days |
| 2026-07-21published 2026-04-14 | GHSA-2hx3-vp6r-mg3fCVE-2026-41134 | high | not named as affected when the advisory was published, now names microsoft.openapi.kiota.builder | Time to revision 98 days |
| Thu 16 Jul 2026· 1 change | ||||
| 2026-07-16published 2024-05-30 | GHSA-22q7-cg4r-p9mx | moderate | not named as affected when the advisory was published, now names typo3/cms-fluid | Time to revision 777 days |
| Wed 15 Jul 2026· 1 change | ||||
| 2026-07-15published 2025-12-01 | GHSA-rcmh-qjqh-p98vCVE-2025-14874 | high | not named as affected when the advisory was published, now names org.webjars.npm:nodemailer | Time to revision 226 days |
| Tue 7 Jul 2026· 1 change | ||||
| 2026-07-07published 2026-05-08 | GHSA-mx76-r943-rf8gCVE-2026-8149 | moderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8on | Time to revision 61 days |
| Mon 6 Jul 2026· 15 changes | ||||
| 2026-07-06published 2026-06-18 | GHSA-jc38-x7x8-2xc8 | high | not named as affected when the advisory was published, now names web-token/jwt-bundle | Time to revision 18 days |
| 2026-07-06published 2026-06-18 | GHSA-jc38-x7x8-2xc8 | high | not named as affected when the advisory was published, now names web-token/jwt-experimental | Time to revision 18 days |
| 2026-07-06published 2026-06-26 | GHSA-6q7j-xr26-3h2c | moderate | not named as affected when the advisory was published, now names scriban.signed | Time to revision 10 days |
| 2026-07-06published 2026-03-24 | GHSA-xw6w-9jjh-p9cr | moderate | not named as affected when the advisory was published, now names scriban.signed | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | GHSA-m2p3-hwv5-xpqw | moderate | not named as affected when the advisory was published, now names scriban.signed | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | GHSA-xcx6-vp38-8hr5 | high | not named as affected when the advisory was published, now names scriban.signed | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | GHSA-v66j-x4hw-fv9g | high | not named as affected when the advisory was published, now names scriban.signed | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | GHSA-5wr9-m6jw-xx44 | critical | not named as affected when the advisory was published, now names scriban.signed | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | GHSA-x6m9-38vm-2xhf | high | not named as affected when the advisory was published, now names scriban.signed | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | GHSA-p6q4-fgr8-vx4p | high | not named as affected when the advisory was published, now names scriban.signed | Time to revision 104 days |
| 2026-07-06published 2026-03-19 | GHSA-5rpf-x9jg-8j5p | moderate | not named as affected when the advisory was published, now names scriban.signed | Time to revision 109 days |
| 2026-07-06published 2026-03-19 | GHSA-grr9-747v-xvcp | high | not named as affected when the advisory was published, now names scriban.signed | Time to revision 109 days |
| 2026-07-06published 2026-03-19 | GHSA-wgh7-7m3c-fx25 | high | not named as affected when the advisory was published, now names scriban.signed | Time to revision 109 days |
| 2026-07-06published 2026-06-26 | GHSA-q6rr-fm2g-g5x8 | moderate | not named as affected when the advisory was published, now names scriban.signed | Time to revision 10 days |
| 2026-07-06published 2026-03-24 | GHSA-c875-h985-hvrc | high | not named as affected when the advisory was published, now names scriban.signed | Time to revision 104 days |
| Wed 1 Jul 2026· 5 changes | ||||
| 2026-07-01published 2024-11-07 | GHSA-7jqf-v358-p8g7CVE-2024-38286 | high | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Time to revision 601 days |
| 2026-07-01published 2024-11-07 | GHSA-7jqf-v358-p8g7CVE-2024-38286 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 601 days |
| 2026-07-01published 2025-08-13 | GHSA-23hv-mwm6-g8jfCVE-2025-55668 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Time to revision 322 days |
| 2026-07-01published 2025-07-10 | GHSA-4j3c-42xv-3f84CVE-2025-52434 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Time to revision 356 days |
| 2026-07-01published 2025-07-10 | GHSA-4j3c-42xv-3f84CVE-2025-52434 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 356 days |
| Mon 29 Jun 2026· 3 changes | ||||
| 2026-06-29published 2026-02-17 | GHSA-qq5r-98hh-rxc9CVE-2026-24733 | low | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 132 days |
| 2026-06-29published 2026-05-19 | GHSA-24c8-4792-22hx | high | not named as affected when the advisory was published, now names scriban.signed | Time to revision 41 days |
| 2026-06-29published 2019-10-11 | GHSA-p979-4mfw-53vgCVE-2019-16869 | high | not named as affected when the advisory was published, now names io.netty:netty | Duration unknown |
| Fri 26 Jun 2026· 2 changes | ||||
| 2026-06-26published 2026-05-29 | GHSA-6x26-5727-rrm9CVE-2026-47268 | moderate | not named as affected when the advisory was published, now names github.com/naiba/nezha | Time to revision 28 days |
| 2026-06-26published 2026-06-10 | GHSA-8h84-fhqq-q58vCVE-2026-48025 | moderate | not named as affected when the advisory was published, now names github.com/forgekeep/nebula-mesh | Time to revision 16 days |
| Thu 18 Jun 2026· 7 changes | ||||
| 2026-06-18published 2024-01-19 | GHSA-f4qf-m5gf-8jm8CVE-2024-21733 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat.experimental:tomcat-embed-programmatic | Time to revision 881 days |
| 2026-06-18published 2026-04-09 | GHSA-x4m4-345f-5h5gCVE-2026-34487 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribes | Time to revision 70 days |
| 2026-06-18published 2024-11-18 | GHSA-f632-9449-3j4wCVE-2024-52318 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-jasper | Time to revision 577 days |
| 2026-06-18published 2024-11-18 | GHSA-f632-9449-3j4wCVE-2024-52318 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat | Time to revision 577 days |
| 2026-06-18published 2023-02-20 | GHSA-hfrx-6qgj-fp6cCVE-2023-24998 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina | Time to revision 1,214 days |
| 2026-06-18published 2019-05-30 | GHSA-jjpq-gp5q-8q6wCVE-2019-0221 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat | Duration unknown |
| 2026-06-18published 2019-05-30 | GHSA-jjpq-gp5q-8q6wCVE-2019-0221 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina | Duration unknown |
| Fri 12 Jun 2026· 4 changes | ||||
| 2026-06-12published 2023-10-10 | GHSA-r6j3-px5g-cq3xCVE-2023-45648 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 976 days |
| 2026-06-12published 2023-10-10 | GHSA-g8pj-r55q-5c2vCVE-2023-42795 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina | Time to revision 976 days |
| 2026-06-12published 2023-10-10 | GHSA-g8pj-r55q-5c2vCVE-2023-42795 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-util | Time to revision 976 days |
| 2026-06-12published 2026-02-17 | GHSA-fpj8-gq4v-p354CVE-2025-66614 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 115 days |
| Thu 11 Jun 2026· 4 changes | ||||
| 2026-06-11published 2026-05-07 | GHSA-2mh5-3cw6-hrrqCVE-2026-40981 | high | not named as affected when the advisory was published, now names org.springframework.cloud:spring-cloud-config-server | Time to revision 35 days |
| 2026-06-11published 2022-02-08 | GHSA-m7jv-hq7h-mq7cCVE-2020-13935 | high | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocket | Duration unknown |
| 2026-06-11published 2022-02-08 | GHSA-m7jv-hq7h-mq7cCVE-2020-13935 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-websocket | Duration unknown |
| 2026-06-11published 2022-02-09 | GHSA-53hp-jpwq-2jgqCVE-2020-11996 | high | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Duration unknown |
| Tue 9 Jun 2026· 1 change | ||||
| 2026-06-09published 2026-06-01 | GHSA-q53q-5r4j-5729CVE-2026-47425 | moderate | not named as affected when the advisory was published, now names py-rattler | Time to revision 8 days |
| Mon 8 Jun 2026· 4 changes | ||||
| 2026-06-08published 2026-05-15 | GHSA-w42g-jj8w-fj77 | high | not named as affected when the advisory was published, now names thorsten/phpmyfaq | Time to revision 24 days |
| 2026-06-08published 2021-04-13 | GHSA-3pcr-4982-548m | moderate | not named as affected when the advisory was published, now names shopware/shopware | Duration unknown |
| 2026-06-08published 2025-10-15 | GHSA-6p6v-m64v-jx8qCVE-2025-55039 | low | not named as affected when the advisory was published, now names pyspark | Time to revision 236 days |
| 2026-06-08published 2026-03-25 | GHSA-7h8w-hj9j-8rjwCVE-2026-33718 | high | not named as affected when the advisory was published, now names openhands-ai | Time to revision 75 days |
| Fri 5 Jun 2026· 4 changes | ||||
| 2026-06-05published 2023-08-25 | GHSA-q3mw-pvr8-9ggcCVE-2023-41080 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina | Time to revision 1,015 days |
| 2026-06-05published 2021-06-16 | GHSA-j39c-c8hj-x4j3CVE-2021-25122 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Duration unknown |
| 2026-06-05published 2026-04-18 | GHSA-w9r4-94fj-xp69CVE-2026-32690 | low | not named as affected when the advisory was published, now names apache-airflow | Time to revision 48 days |
| 2026-06-05published 2025-09-24 | GHSA-776q-jw43-fhjxCVE-2025-48459 | critical | not named as affected when the advisory was published, now names apache-iotdb | Time to revision 254 days |
| Mon 1 Jun 2026· 2 changes | ||||
| 2026-06-01published 2026-05-18 | GHSA-v549-xx3c-6pc8CVE-2026-3637 | moderate | not named as affected when the advisory was published, now names github.com/mattermost/mattermost-server | Time to revision 14 days |
| 2026-06-01published 2026-05-18 | GHSA-v549-xx3c-6pc8CVE-2026-3637 | moderate | not named as affected when the advisory was published, now names github.com/mattermost/mattermost/server/v8 | Time to revision 14 days |
| Fri 29 May 2026· 1 change | ||||
| 2026-05-29published 2026-04-22 | GHSA-ffq5-qpvf-xq7xCVE-2026-42086 | moderate | not named as affected when the advisory was published, now names openc3 | Time to revision 37 days |
| Wed 20 May 2026· 8 changes | ||||
| 2026-05-20published 2023-06-14 | GHSA-5wfc-hjrc-gq87CVE-2023-34620 | high | not named as affected when the advisory was published, now names github.com/hjson/hjson-go/v4 | Time to revision 1,071 days |
| 2026-05-20published 2023-06-14 | GHSA-5wfc-hjrc-gq87CVE-2023-34620 | high | not named as affected when the advisory was published, now names laktak/hjson | Time to revision 1,071 days |
| 2026-05-20published 2026-04-09 | GHSA-69cc-cv78-qc8gCVE-2026-29129 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 41 days |
| 2026-05-20published 2026-04-09 | GHSA-95jq-rwvf-vjx4CVE-2026-29145 | critical | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote-ffm | Time to revision 41 days |
| 2026-05-20published 2024-12-17 | GHSA-653p-vg55-5652CVE-2024-54677 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat | Time to revision 519 days |
| 2026-05-20published 2020-06-15 | GHSA-qcxh-w3j9-58qrCVE-2019-0199 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Duration unknown |
| 2026-05-20published 2026-04-09 | GHSA-24j9-x2wg-9qv6CVE-2026-34500 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote-ffm | Time to revision 40 days |
| 2026-05-20published 2026-03-31 | GHSA-rvhj-8chj-8v3cCVE-2026-0596 | critical | not named as affected when the advisory was published, now names mlflow | Time to revision 49 days |
| Thu 14 May 2026· 3 changes | ||||
| 2026-05-14published 2024-12-02 | GHSA-4cx5-89vm-833xCVE-2024-52800 | low | not named as affected when the advisory was published, now names org.verapdf:library | Time to revision 528 days |
| 2026-05-14published 2024-12-02 | GHSA-4cx5-89vm-833xCVE-2024-52800 | low | not named as affected when the advisory was published, now names org.verapdf:library-arlington | Time to revision 528 days |
| 2026-05-14published 2024-12-02 | GHSA-4cx5-89vm-833xCVE-2024-52800 | low | not named as affected when the advisory was published, now names org.verapdf:library-jakarta | Time to revision 528 days |
| Thu 7 May 2026· 7 changes | ||||
| 2026-05-07published 2025-08-08 | GHSA-hj95-mhgf-jxc4CVE-2025-30404 | critical | not named as affected when the advisory was published, now names github.com/pytorch/executorch | Time to revision 273 days |
| 2026-05-07published 2025-08-08 | GHSA-xc7w-r669-48pfCVE-2025-54951 | critical | not named as affected when the advisory was published, now names github.com/pytorch/executorch | Time to revision 273 days |
| 2026-05-07published 2026-03-16 | GHSA-6jj5-j4j8-8473CVE-2026-28499 | moderate | not named as affected when the advisory was published, now names github.com/vapor/leaf-kit | Time to revision 52 days |
| 2026-05-07published 2025-08-08 | GHSA-84m3-f99p-cqx5CVE-2025-30405 | critical | not named as affected when the advisory was published, now names github.com/pytorch/executorch | Time to revision 273 days |
| 2026-05-07published 2025-08-08 | GHSA-9m39-3mf3-xwchCVE-2025-54949 | critical | not named as affected when the advisory was published, now names github.com/pytorch/executorch | Time to revision 273 days |
| 2026-05-07published 2025-08-08 | GHSA-f9hx-c6jf-3qxmCVE-2025-54950 | critical | not named as affected when the advisory was published, now names github.com/pytorch/executorch | Time to revision 273 days |
| 2026-05-07published 2025-07-11 | GHSA-h952-963h-rv99CVE-2025-30402 | high | not named as affected when the advisory was published, now names github.com/pytorch/executorch | Time to revision 300 days |
| Wed 6 May 2026· 9 changes | ||||
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | high | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/auth-helpers | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | high | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/aws-secrets-manager | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | high | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/federated-auth | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | high | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/iam | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | high | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/mysql-driver | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | high | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/okta | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | high | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/otlp | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | high | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/pgx-driver | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | high | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/xray | Time to revision 174 days |
| Tue 5 May 2026· 1 change | ||||
| 2026-05-05published 2025-09-03 | GHSA-qww7-89xh-x7m7CVE-2025-55747 | critical | not named as affected when the advisory was published, now names org.xwiki.platform:xwiki-platform-webjars | Time to revision 244 days |
| Tue 28 Apr 2026· 2 changes | ||||
| 2026-04-28published 2026-04-09 | GHSA-563x-q5rq-57qpCVE-2026-24880 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 18 days |
| 2026-04-28published 2022-02-08 | GHSA-vf77-8h7g-gghpCVE-2020-13934 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Duration unknown |
| Wed 22 Apr 2026· 1 change | ||||
| 2026-04-22published 2026-02-19 | GHSA-4hfh-fch3-5q7pCVE-2026-27120 | moderate | not named as affected when the advisory was published, now names github.com/vapor/leaf-kit | Time to revision 62 days |
Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory and per package, so one advisory that named four further packages counts four times.
What this page cannot see
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →
Paste your closed CVE tickets and see which of these changes hit them →