Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 23 Jan 2026· 14 advisory changes
2026-01-23published 2021-08-25Advisory withdrawnGHSA-gq4h-f254-7cw9whole advisoryhighwithdrawn 2026-01-23Days to revision 1,612
2026-01-23published 2024-05-30Advisory withdrawnGHSA-7fpj-wc8v-9cgcwhole advisorycriticalwithdrawn 2026-01-23Days to revision 603
2026-01-23published 2024-05-28Advisory withdrawnGHSA-fjr2-r2mp-484pwhole advisorycriticalwithdrawn 2026-01-23Days to revision 605
2026-01-23published 2021-08-25Advisory withdrawnGHSA-r88h-6987-g79fwhole advisoryhighwithdrawn 2026-01-23Days to revision 1,612
2026-01-23published 2022-12-28Advisory withdrawnGHSA-3839-6r69-m497whole advisorycriticalwithdrawn 2026-01-23Days to revision 1,123
2026-01-23published 2019-05-29Advisory withdrawnGHSA-qr32-j4j6-3m7rCVE-2017-16087whole advisoryhighwithdrawn 2026-01-23Days to revision 2,431
2026-01-23published 2020-09-03Advisory withdrawnGHSA-8whr-v3gm-w8h9whole advisoryhighwithdrawn 2026-01-23Days to revision 1,968
2026-01-23published 2021-06-21Advisory withdrawnGHSA-5w25-hxp5-h8c9whole advisorycriticalwithdrawn 2026-01-23Days to revision 1,677
2026-01-23published 2022-02-01Advisory withdrawnGHSA-9chx-2vqw-8vq5CVE-2022-23409whole advisorymoderatewithdrawn 2026-01-23Days to revision 1,453
2026-01-23published 2022-12-28Advisory withdrawnGHSA-jpgg-cp2x-qrw3whole advisorycriticalwithdrawn 2026-01-23Days to revision 1,123
2026-01-23published 2024-02-06Advisory withdrawnGHSA-w277-wpqf-rcfvwhole advisorymoderatewithdrawn 2026-01-23Days to revision 717
2026-01-23published 2022-12-28Advisory withdrawnGHSA-967g-cjx4-h7j6whole advisoryhighwithdrawn 2026-01-23Days to revision 1,123
2026-01-23published 2021-08-25Advisory withdrawnGHSA-wcxc-jf6c-8rx9whole advisorymoderatewithdrawn 2026-01-23Days to revision 1,612
2026-01-23published 2022-03-05Advisory withdrawnGHSA-h2g5-2rhx-ffgjCVE-2022-24727whole advisoryhighwithdrawn 2026-01-23Days to revision 1,421
Thu 22 Jan 2026· 17 advisory changes
2026-01-22published 2022-04-12Advisory severity changedGHSA-2xxx-fhc8-9qvqCVE-2017-20166whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2026-01-22published 2026-01-14Advisory severity changedGHSA-g9mf-h72j-4rw9CVE-2026-22036whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2026-01-22published 2021-08-30Advisory withdrawnGHSA-6gvc-4jvj-pwq4whole advisorymoderatewithdrawn 2026-01-22Days to revision 1,606
2026-01-22published 2022-05-24Advisory withdrawnGHSA-j7j6-7hfx-5522whole advisoryhighwithdrawn 2026-01-22Days to revision 1,339
2026-01-22published 2021-05-10Advisory withdrawnGHSA-r2gr-fhmr-66c5whole advisoryhighwithdrawn 2026-01-22Days to revision 1,718
2026-01-22published 2024-01-19Advisory withdrawnGHSA-hj55-9jmv-9jrjwhole advisoryhighwithdrawn 2026-01-22Days to revision 734
2026-01-22published 2024-01-19Advisory withdrawnGHSA-hfj8-63c8-rmfwwhole advisoryhighwithdrawn 2026-01-22Days to revision 734
2026-01-22published 2024-01-19Advisory withdrawnGHSA-gvc7-gjrw-hj65whole advisorymoderatewithdrawn 2026-01-22Days to revision 734
2026-01-22published 2024-01-19Advisory withdrawnGHSA-4hrp-m3f2-643jwhole advisorycriticalwithdrawn 2026-01-22Days to revision 734
2026-01-22published 2023-09-28Advisory withdrawnGHSA-9xfq-8j3r-xp5gwhole advisorycriticalwithdrawn 2026-01-22Days to revision 848
2026-01-22published 2024-01-19Advisory withdrawnGHSA-hv5g-q4h3-64q4whole advisorymoderatewithdrawn 2026-01-22Days to revision 734
2026-01-22published 2023-01-10Advisory withdrawnGHSA-4r2f-6fm9-2qghwhole advisorycriticalwithdrawn 2026-01-22Days to revision 1,109
2026-01-22published 2024-01-19Advisory withdrawnGHSA-wc6f-qjxc-622vwhole advisorymoderatewithdrawn 2026-01-22Days to revision 734
2026-01-22published 2024-01-19Advisory withdrawnGHSA-3p77-wg4c-qm24whole advisoryhighwithdrawn 2026-01-22Days to revision 734
2026-01-22published 2024-01-19Advisory withdrawnGHSA-23rx-79r7-6cpxwhole advisoryhighwithdrawn 2026-01-22Days to revision 734
2026-01-22published 2024-01-19Advisory withdrawnGHSA-c4pg-5ggh-vcppwhole advisoryhighwithdrawn 2026-01-22Days to revision 734
2026-01-22published 2024-01-20Advisory withdrawnGHSA-9rhq-86fm-qxqcwhole advisorycriticalwithdrawn 2026-01-22Days to revision 734
Wed 21 Jan 2026· 3 advisory changes
2026-01-21published 2025-05-07Package added to advisoryGHSA-72qj-48g4-5xgxCVE-2025-46551moderatenot named as affected when the advisory was published, now names jruby-opensslDays to revision 259
2026-01-21published 2026-01-20Advisory severity changedGHSA-gfpw-jgvr-cw4jCVE-2026-22808whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
2026-01-21published 2026-01-21Advisory severity changedGHSA-2762-657x-v979CVE-2026-23885whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
Fri 16 Jan 2026· 1 advisory change
2026-01-16published 2025-10-21Package added to advisoryGHSA-j5gw-2vrg-8fgxCVE-2025-62518highnot named as affected when the advisory was published, now names tokio-tarDays to revision 87
Thu 8 Jan 2026· 1 advisory change
2026-01-08published 2026-01-07Advisory severity changedGHSA-5f29-2333-h9c7CVE-2026-22244whole advisoryhighstated at publication CRITICAL, now states HIGHA CVSS version was added; the existing vectors stayed the same.Days to revision 1
Wed 7 Jan 2026· 1 advisory change
2026-01-07published 2025-11-07Advisory fix version movedGHSA-f83h-ghpp-7wccCVE-2025-70559
pypipdfminer.six
high
stated at publication 20251107, now states 20251230Days to revision 7
Tue 6 Jan 2026· 3 advisory changes
2026-01-06published 2025-12-17Advisory fix version movedGHSA-3677-xxcr-wjqvCVE-2024-29371
mavenorg.bitbucket.b_c:jose4j
high
stated at publication 0.9.5, now states 0.9.6Days to revision 20
2026-01-06published 2025-12-31Package added to advisoryGHSA-mrfv-m5wm-5w6wCVE-2025-69277moderatenot named as affected when the advisory was published, now names hdwalletDays to revision 7
2026-01-06published 2025-12-31Package added to advisoryGHSA-mrfv-m5wm-5w6wCVE-2025-69277moderatenot named as affected when the advisory was published, now names pynaclDays to revision 7
Mon 5 Jan 2026· 1 advisory change
2026-01-05published 2026-01-02Package added to advisoryGHSA-c5cp-vx83-jhqxCVE-2026-21445highnot named as affected when the advisory was published, now names langflowDays to revision 2
Fri 2 Jan 2026· 1 advisory change
2026-01-02published 2025-12-30Advisory severity changedGHSA-95qg-89c2-w5hjCVE-2025-69257whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 3
Thu 1 Jan 2026· 1 advisory change
2026-01-01published 2025-12-20Advisory severity changedGHSA-83jg-m2pm-4jxjCVE-2025-34469whole advisorymoderatestated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same.Days to revision 11
Mon 29 Dec 2025· 4 advisory changes
2025-12-29published 2024-10-02Advisory withdrawnGHSA-r2jw-c95q-rj29whole advisorymoderatewithdrawn 2025-12-29Days to revision 454
2025-12-29published 2025-05-09Advisory withdrawnGHSA-c86p-w88r-qvqrwhole advisorymoderatewithdrawn 2025-12-29Days to revision 234
2025-12-29published 2025-12-08Advisory withdrawnGHSA-95fv-5gfj-2r84CVE-2025-64113whole advisorycriticalwithdrawn 2025-12-29Days to revision 21
2025-12-29published 2021-12-10Advisory withdrawnGHSA-49vv-6q7q-w5cfwhole advisoryhighwithdrawn 2025-12-29Days to revision 1,480
Tue 23 Dec 2025· 1 advisory change
2025-12-23published 2025-12-23Advisory severity changedGHSA-pp3g-xmm4-5cw9CVE-2025-65713whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 0
Mon 22 Dec 2025· 3 advisory changes
2025-12-22published 2025-06-23Advisory fix version movedGHSA-9623-mj7j-p9v4CVE-2025-49574
mavenio.quarkus:quarkus-vertx
moderate
stated at publication 3.24.0, now states 3.24.1Days to revision 182
2025-12-22published 2022-01-06Package added to advisoryGHSA-x8rq-rc7x-5fg5CVE-2022-0086highnot named as affected when the advisory was published, now names @uppy/companionnot dated
2025-12-22published 2025-12-15Advisory withdrawnGHSA-vr6p-vq2p-6j74whole advisorycriticalwithdrawn 2025-12-22Days to revision 7
Fri 19 Dec 2025· 1 advisory change
2025-12-19published 2025-11-25Advisory withdrawnGHSA-93vm-mqpw-8wh3whole advisorymoderatewithdrawn 2025-12-19Days to revision 24
Thu 18 Dec 2025· 5 advisory changes
2025-12-18published 2022-11-01Package added to advisoryGHSA-43xg-8wmj-cw8hCVE-2022-31777moderatenot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.10not dated
2025-12-18published 2022-11-01Package added to advisoryGHSA-43xg-8wmj-cw8hCVE-2022-31777moderatenot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.11not dated
2025-12-18published 2022-11-01Package added to advisoryGHSA-43xg-8wmj-cw8hCVE-2022-31777moderatenot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.12not dated
2025-12-18published 2022-11-01Package added to advisoryGHSA-43xg-8wmj-cw8hCVE-2022-31777moderatenot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.13not dated
2025-12-18published 2022-11-01Package added to advisoryGHSA-43xg-8wmj-cw8hCVE-2022-31777moderatenot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.9.3not dated
Tue 16 Dec 2025· 18 advisory changes
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_0.25not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_0.27not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.10not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.11not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.12not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13.0-m5not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13.0-rc1not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13.0-rc2not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13.0-rc3not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_3not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_3.0.0-m1not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_3.0.0-m2not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_3.0.0-m3not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_3.0.0-rc1not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_3.0.0-rc2not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_3.0.0-rc3not dated
2025-12-16published 2022-01-06Package added to advisoryGHSA-vc89-hccf-rq55CVE-2022-21653moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parsergnot dated
Thu 11 Dec 2025· 25 advisory changes
2025-12-11published 2021-09-02Package added to advisoryGHSA-52cf-226f-rhr6CVE-2021-39185criticalnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.10not dated
2025-12-11published 2021-09-02Package added to advisoryGHSA-52cf-226f-rhr6CVE-2021-39185criticalnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.11not dated
2025-12-11published 2021-09-02Package added to advisoryGHSA-52cf-226f-rhr6CVE-2021-39185criticalnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.12not dated
2025-12-11published 2021-09-02Package added to advisoryGHSA-52cf-226f-rhr6CVE-2021-39185criticalnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.13not dated
2025-12-11published 2021-09-02Package added to advisoryGHSA-52cf-226f-rhr6CVE-2021-39185criticalnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.13.0-m5not dated
2025-12-11published 2021-09-02Package added to advisoryGHSA-52cf-226f-rhr6CVE-2021-39185criticalnot named as affected when the advisory was published, now names org.http4s:http4s-server_3not dated
2025-12-11published 2021-09-22Package added to advisoryGHSA-5vcm-3xc3-w7x3CVE-2021-41084highnot named as affected when the advisory was published, now names org.http4s:http4s-client_2.12not dated
2025-12-11published 2021-09-22Package added to advisoryGHSA-5vcm-3xc3-w7x3CVE-2021-41084highnot named as affected when the advisory was published, now names org.http4s:http4s-client_2.13not dated
2025-12-11published 2021-09-22Package added to advisoryGHSA-5vcm-3xc3-w7x3CVE-2021-41084highnot named as affected when the advisory was published, now names org.http4s:http4s-client_3not dated
2025-12-11published 2021-09-22Package added to advisoryGHSA-5vcm-3xc3-w7x3CVE-2021-41084highnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.10not dated
2025-12-11published 2021-09-22Package added to advisoryGHSA-5vcm-3xc3-w7x3CVE-2021-41084highnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.11not dated
2025-12-11published 2021-09-22Package added to advisoryGHSA-5vcm-3xc3-w7x3CVE-2021-41084highnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.12not dated
2025-12-11published 2021-09-22Package added to advisoryGHSA-5vcm-3xc3-w7x3CVE-2021-41084highnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.13not dated
2025-12-11published 2021-09-22Package added to advisoryGHSA-5vcm-3xc3-w7x3CVE-2021-41084highnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.13.0-m5not dated
2025-12-11published 2021-09-22Package added to advisoryGHSA-5vcm-3xc3-w7x3CVE-2021-41084highnot named as affected when the advisory was published, now names org.http4s:http4s-server_3not dated
2025-12-11published 2023-01-06Package added to advisoryGHSA-54w6-vxfh-fw7fCVE-2023-22465highnot named as affected when the advisory was published, now names org.http4s:http4s-core_2.10Days to revision 1,070
2025-12-11published 2023-01-06Package added to advisoryGHSA-54w6-vxfh-fw7fCVE-2023-22465highnot named as affected when the advisory was published, now names org.http4s:http4s-core_2.11Days to revision 1,070
2025-12-11published 2023-01-06Package added to advisoryGHSA-54w6-vxfh-fw7fCVE-2023-22465highnot named as affected when the advisory was published, now names org.http4s:http4s-core_2.12Days to revision 1,070
2025-12-11published 2023-01-06Package added to advisoryGHSA-54w6-vxfh-fw7fCVE-2023-22465highnot named as affected when the advisory was published, now names org.http4s:http4s-core_2.13Days to revision 1,070
2025-12-11published 2022-05-14Package added to advisoryGHSA-62g2-m955-v383CVE-2018-11804highnot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.10not dated
2025-12-11published 2022-05-14Package added to advisoryGHSA-62g2-m955-v383CVE-2018-11804highnot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.11not dated
2025-12-11published 2025-06-10Package added to advisoryGHSA-76qp-h5mr-frr4CVE-2025-27818highnot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.11Days to revision 185
2025-12-11published 2025-06-10Package added to advisoryGHSA-76qp-h5mr-frr4CVE-2025-27818highnot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.12Days to revision 185
2025-12-11published 2025-06-10Package added to advisoryGHSA-76qp-h5mr-frr4CVE-2025-27818highnot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.13Days to revision 185
2025-12-11published 2025-06-10Package added to advisoryGHSA-mcwh-c9pg-xw43CVE-2025-27819highnot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.10Days to revision 185

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →