Skip to content

Package advisories

Maven

718advisory rows483advisories458packagesRSSas of the 2026-09-07 snapshot

An advisory is the GHSA entry a Dependabot alert links to; GitHub-reviewed only. One row is one change to one package: 36 fixed-in version changed, 682 package added later.

No rate: 35,259 advisories were compared across every ecosystem together, and the analysis carries no count of how many were Maven, so nothing here divides one number by the other.

Kind of change

718 counted rows, shown as 37 lines because the same change repeated is shown once · newest advisory first

Changes to GitHub-reviewed advisories naming a package in maven. Each row gives the kind of change and the advisory it happened to. Where the same change was made to several advisories or packages at once, one row stands for all of them, says how many, and opens to every one. Then the ecosystem and package, what the advisory said beside what it says now, GitHub's severity level, and the date the advisory was published.
Package, The package the change names, or where one row stands for the same change across several packages, how many.Kind of changeAdvisory, The advisory id, or where one row stands for the same change made to several advisories, how many it stands for. An advisory id links to GitHub, and a CVE id is shown beside it where the advisory names one.What changedSeverity, GitHub's severity level for the advisory as it stands today: low, moderate, high or critical. Where one row stands for advisories at more than one level, it says how many levels, never one of them.Advisory published, The date the advisory was published. Every lag on this source is measured from it, and it is a third clock beside the CVE catalog's publication date and the date CISA added an entry to KEV. Two kinds of change also carry a date of their own: a withdrawal states its own timestamp, and a changed fix version is dated by reading back through the dated saves of the advisory file until the one where the version first reached the value it has today. A package added and a severity changed leave no commit of their own to date, so for those the date of the change is not recorded at all. That is absence, never same-day.
io.openremote:openremote-managerAdvisory fix version movedGHSA-h3m5-97jq-qjrfCVE-2026-57168stated at publication 1.24.2, now states 1.25.0critical2026-06-19
434 packages682 rows, one per advisory and packagePackage added to advisory454 advisoriesnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote and 433 more4 severity levels2017-10-24 to2026-05-12
org.apache.tomcat:tomcat-coyotesame kind of edit as the line aboveGHSA-r29c-68gh-xp6xCVE-2026-41293not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyotecritical2026-05-12
org.bouncycastle:bcprov-lts8onsame kind of edit as the line aboveGHSA-mx76-r943-rf8gCVE-2026-8149not named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8onmoderate2026-05-08
org.springframework.cloud:spring-cloud-config-serversame kind of edit as the line aboveGHSA-2mh5-3cw6-hrrqCVE-2026-40981not named as affected when the advisory was published, now names org.springframework.cloud:spring-cloud-config-serverhigh2026-05-07
io.netty:netty-transport-classes-epollsame kind of edit as the line aboveGHSA-rwm7-x88c-3g2pCVE-2026-42577not named as affected when the advisory was published, now names io.netty:netty-transport-classes-epollhigh2026-05-06
com.coravy.hudson.plugins.github:githubsame kind of edit as the line aboveGHSA-w22p-4x9f-486vCVE-2026-42523not named as affected when the advisory was published, now names com.coravy.hudson.plugins.github:githubcritical2026-04-29
org.apache.tomcat:tomcat-coyote-ffmsame kind of edit as the line aboveGHSA-24j9-x2wg-9qv6CVE-2026-34500not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote-ffmmoderate2026-04-09
org.apache.tomcat:tomcat-tribessame kind of edit as the line aboveGHSA-69r9-qgr7-g2wjCVE-2026-34486not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribeshigh2026-04-09
org.apache.tomcat:tomcat-tribessame kind of edit as the line aboveGHSA-x4m4-345f-5h5gCVE-2026-34487not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribeshigh2026-04-09
674 more rows in this change are not listed here. Open all 682 rows
com.getaxonflow:axonflow-sdkAdvisory fix version movedGHSA-248h-974q-xrc2stated at publication 6.0.0, now states 7.0.0moderate2026-05-06
org.eclipse.jetty:jetty-httpAdvisory fix version movedGHSA-355h-qmc2-wpwfCVE-2026-2332stated at publication 11.0.28, now states 11.0.29high2026-04-14
org.apache.tomcat:tomcatAdvisory fix version movedGHSA-h468-7pvh-8vr8CVE-2026-29146stated at publication 11.0.19, now states 11.0.20high2026-04-09
org.scala-sbt:sbtAdvisory fix version movedGHSA-x4ff-q6h8-v7gwCVE-2026-32948stated at publication 1.12.7, now states 1.12.8moderate2026-03-24
fr.opensagres.xdocreport:fr.opensagres.xdocreport.template.freemarkerAdvisory fix version movedGHSA-r8w2-w357-9pjvCVE-2025-64087stated at publication 2.1.0, now states 2.2.0critical2026-01-20
org.bitbucket.b_c:jose4jAdvisory fix version movedGHSA-3677-xxcr-wjqvCVE-2024-29371stated at publication 0.9.5, now states 0.9.6high2025-12-17
io.quarkus:quarkus-vertxAdvisory fix version movedGHSA-9623-mj7j-p9v4CVE-2025-49574stated at publication 3.24.0, now states 3.24.1moderate2025-06-23
com.linecorp.centraldogma:centraldogma-serverAdvisory fix version movedGHSA-34q3-p352-c7q8CVE-2024-1143stated at publication 0.64.0, now states 0.64.1critical2024-02-02
org.jenkins-ci.plugins:nodejsAdvisory fix version movedGHSA-36fg-whr2-g999CVE-2023-40340stated at publication 1.6.0.1, now states 1.6.1moderate2023-08-16
com.ruoyi:ruoyiAdvisory fix version movedGHSA-h4c9-rr5m-32fmCVE-2023-27025stated at publication 4.7.6, now states 4.7.7high2023-04-02
org.apache.dubbo:dubboAdvisory fix version movedGHSA-933g-v89r-x8pfCVE-2023-23638stated at publication 2.7.21, now states 2.7.22critical2023-03-08
com.xuxueli:xxl-job-coreAdvisory fix version movedGHSA-83w4-x5w9-hf4hCVE-2022-43183stated at publication 2.3.1, now states 2.4.0high2022-11-17
org.jenkins-ci.plugins:fortify-on-demand-uploaderAdvisory fix version movedGHSA-fhmf-xf2q-4m8pCVE-2020-2204stated at publication 6.0.0, now states 6.0.1moderate2022-05-24
net.bull.javamelody:javamelody-coreAdvisory fix version movedGHSA-p4mx-p49m-8rw4CVE-2013-4378stated at publication 1.46.0, now states 1.47.0moderate2022-05-17
org.sonarsource.sonarqube:sonar-plugin-apiAdvisory fix version movedGHSA-m643-2pfv-xwm8CVE-2018-19413stated at publication 7.4, now states 7.5moderate2022-05-14
org.apache.tomcat:tomcatAdvisory fix version movedGHSA-3gv7-3h64-78cmCVE-2017-5647stated at publication 8.0.42, now states 8.0.43high2022-05-14
org.jenkins-ci.main:jenkins-coreAdvisory fix version movedGHSA-8qpf-fv36-h4r8CVE-2018-1999044stated at publication 2.137, now states 2.138moderate2022-05-13
org.codehaus.groovy:groovyAdvisory fix version movedGHSA-xphj-m9cc-8fmqCVE-2016-6814stated at publication 2.4.4, now states 2.4.8critical2022-05-13
org.jenkins-ci.main:jenkins-coreAdvisory fix version movedGHSA-p265-xr98-3vmrCVE-2018-1999003stated at publication 2.132, now states 2.133moderate2022-05-13
org.apache.struts:struts2-coreAdvisory fix version movedGHSA-hxqq-w4mr-mc62CVE-2012-0393stated at publication 2.2.3.1, now states 2.3.1.1moderate2022-05-04
net.lingala.zip4j:zip4jAdvisory fix version movedGHSA-q62h-jw38-24vhCVE-2022-24615stated at publication 2.9.0, now states 2.10.0moderate2022-02-25
org.apache.tomcat:tomcatAdvisory fix version movedGHSA-m7jv-hq7h-mq7cCVE-2020-13935stated at publication 7.0.104, now states 7.0.105high2022-02-08
org.apache.tomcat:tomcatAdvisory fix version movedGHSA-m7jv-hq7h-mq7cCVE-2020-13935stated at publication 8.5.56, now states 8.5.57high2022-02-08
org.apache.tomcat:tomcatAdvisory fix version movedGHSA-m7jv-hq7h-mq7cCVE-2020-13935stated at publication 9.0.36, now states 9.0.37high2022-02-08
org.springframework.amqp:spring-amqpAdvisory fix version movedGHSA-945q-ch46-pchgCVE-2021-22095stated at publication 2.2.19, now states 2.2.20moderate2021-12-01
org.apache.tomcat:tomcatAdvisory fix version movedGHSA-4vww-mc66-62m6CVE-2021-33037stated at publication 10.0.6, now states 10.0.7moderate2021-08-13
org.apache.tomcat:tomcatAdvisory fix version movedGHSA-4vww-mc66-62m6CVE-2021-33037stated at publication 8.5.66, now states 8.5.68moderate2021-08-13
org.apache.tomcat:tomcatAdvisory fix version movedGHSA-4vww-mc66-62m6CVE-2021-33037stated at publication 9.0.46, now states 9.0.48moderate2021-08-13
dev.personnummer:personnummerAdvisory fix version movedGHSA-q3vw-4jx3-rrr2stated at publication 1.0.1, now states 3.3.0low2020-09-23
commons-beanutils:commons-beanutilsAdvisory fix version movedGHSA-p66x-2cv9-qq3vCVE-2014-0114stated at publication 1.9.2, now states 1.9.4high2020-06-10
org.apache.tomcat.embed:tomcat-embed-coreAdvisory fix version movedGHSA-q4hg-rmq2-52q9CVE-2019-10072stated at publication 8.5.40, now states 8.5.41high2019-06-26
com.thoughtworks.xstream:xstreamAdvisory fix version movedGHSA-f554-x222-wgf7CVE-2013-7285stated at publication 1.4.6, now states 1.4.7critical2019-05-29
org.exist-db:exist-coreAdvisory fix version movedGHSA-jxm5-5xcw-h57qCVE-2018-1000823stated at publication 5.0.0, now states 5.1.0critical2018-12-20
org.apache.solr:solr-coreAdvisory fix version movedGHSA-3pph-2595-cgfhCVE-2018-1308stated at publication 7.2.1, now states 7.3.0high2018-10-17
org.apache.qpid:apache-qpid-broker-jAdvisory fix version movedGHSA-7xr3-rgwh-pw22CVE-2018-8030stated at publication 7.0.5, now states 7.1.0high2018-10-16

718 rows, grouped into 37, all on this page

Every change counted from this source is on this page, so an advisory with no row here had no change of that kind. No finding here is not an all clear. It means this check found nothing in the history it can see, not that nothing happened.

A grouped row is the same change, repeated. Where one change was made to many packages or many advisories, the advisory column says how many it stands for instead of naming one, and opens to every one of them. It may have been one edit or many: what the grouping states is that the change is identical, not that it was made in one act.

A fixed-in version is compared within one release branch, keyed by the range's introduced value. An advisory listing a fix for 4.1.x and another for 4.2.x states two of them, and taking the highest version across the whole package would report a newly added branch as though an existing branch's fix had changed.

82 more advisories that name a package in maven had the severity changed, or the whole advisory withdrawn. None of it is counted in any figure above. Open to read it.

A severity level and a withdrawal belong to the whole advisory. The advisory database records neither against a package, so neither can be attributed to an ecosystem. These 82 rows are here for one reason: the same advisory also names a package in maven in the table above. The other 3,098 of the 3,180 cannot be placed in an ecosystem at all.

Severity changes and withdrawals recorded against advisories that also name a package in maven. These rows name no ecosystem of their own and are not counted in this page's ecosystem figures.
Kind of changeAdvisoryWhat changedSeverityAdvisory published
Advisory severity changedGHSA-rcmh-qjqh-p98vCVE-2025-14874stated at publication LOW, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.high2025-12-01
Advisory severity changedGHSA-25xr-qj8w-c4vfCVE-2025-53506stated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.high2025-07-10
Advisory severity changedGHSA-wr62-c79q-cv37CVE-2025-52520stated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.high2025-07-10
Advisory severity changedGHSA-83qj-6fr2-vhqgCVE-2025-24813stated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.critical2025-03-10
Advisory severity changedGHSA-4gc7-5j7h-4qphCVE-2024-38820stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.moderate2024-10-18
Advisory severity changedGHSA-crjg-w57m-rqqfstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.high2024-07-22
Advisory severity changedGHSA-mmwx-rj87-vfgrstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.high2024-07-22
Advisory withdrawnGHSA-9mvj-f7w8-pvh2CVE-2024-6484withdrawn 2025-09-11moderate2024-07-11
Advisory withdrawnGHSA-vc8w-jr9v-vj7fCVE-2024-6531withdrawn 2025-10-09moderate2024-07-11
Advisory severity changedGHSA-4w54-wwc9-x62cCVE-2024-36042stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.critical2024-06-03
Advisory severity changedGHSA-4h8f-2wvx-gg5wCVE-2024-34447stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.moderate2024-05-03
Advisory withdrawnGHSA-r65j-6h5f-4f92CVE-2024-31033withdrawn 2024-04-03moderate2024-04-01
Advisory severity changedGHSA-qmgx-j96g-4428CVE-2024-28752stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.critical2024-03-15
Advisory severity changedGHSA-p5q9-86w4-2xr5CVE-2023-51747stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2024-02-27
Advisory severity changedGHSA-rc6h-qwj9-2c53CVE-2024-23320stated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.high2024-02-23
Advisory severity changedGHSA-xrj7-x7gp-wwqrCVE-2023-50298stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.moderate2024-02-09
Advisory severity changedGHSA-9gh8-877r-g477CVE-2024-22533stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.critical2024-02-02
Advisory severity changedGHSA-hr2c-p8rh-238hCVE-2023-51441stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2024-01-06
Advisory severity changedGHSA-fccv-jmmp-qg76CVE-2023-46589stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2023-11-28
Advisory severity changedGHSA-q24v-hpg3-v3jpCVE-2023-34054stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.high2023-11-28
Advisory severity changedGHSA-wjxj-5m7g-mg7qCVE-2023-33202stated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.moderate2023-11-23
Advisory severity changedGHSA-cqpc-x2c6-2gmfCVE-2023-41339stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.moderate2023-10-24
Advisory severity changedGHSA-rp6x-ggw6-8g56CVE-2023-43668stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.critical2023-10-16
Advisory severity changedGHSA-q3mw-pvr8-9ggcCVE-2023-41080stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.moderate2023-08-25
Advisory severity changedGHSA-rg2c-cfxv-qp6fCVE-2023-3894stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.high2023-08-08
Advisory severity changedGHSA-7gj7-224w-vpr3CVE-2023-38286stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2023-07-14
Advisory withdrawnGHSA-257q-pv89-v3xvCVE-2020-23064withdrawn 2024-05-15moderate2023-06-26
Advisory severity changedGHSA-mppv-79ch-vw6qCVE-2023-34981stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2023-06-21
Advisory severity changedGHSA-4g42-gqrg-4633CVE-2023-34396stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.high2023-06-14
Advisory severity changedGHSA-65wh-g8x8-gm2hCVE-2023-34212stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.moderate2023-06-12
Advisory severity changedGHSA-564r-hj7v-mcr5CVE-2023-20861stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.moderate2023-03-23
Advisory severity changedGHSA-vp98-w2p3-mv35CVE-2023-26464stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2023-03-10
Advisory severity changedGHSA-933g-v89r-x8pfCVE-2023-23638stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.critical2023-03-08
Advisory severity changedGHSA-j75r-vf64-6rrhCVE-2023-0481stated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.low2023-02-24
Advisory withdrawnGHSA-jrmh-v64j-mjm9withdrawn 2025-01-15moderate2023-02-18
Advisory severity changedGHSA-rq2w-37h9-vg94CVE-2022-45143stated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.high2023-01-03
Advisory severity changedGHSA-w9rv-xmf7-x3ghCVE-2022-44621stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.critical2022-12-30
Advisory severity changedGHSA-54r5-wr8x-x5v3stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-12-20
Advisory withdrawnGHSA-54r5-wr8x-x5v3withdrawn 2024-10-07high2022-12-20
Advisory severity changedGHSA-3vqj-43w4-2q58CVE-2022-45688stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-12-13
Advisory severity changedGHSA-g56w-cwg4-hxx9CVE-2022-4116stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.critical2022-11-22
Advisory severity changedGHSA-43xg-8wmj-cw8hCVE-2022-31777stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.moderate2022-11-01
Advisory severity changedGHSA-p22x-g9px-3945CVE-2022-42252stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-11-01
Advisory severity changedGHSA-g6hg-4v3c-6jq7CVE-2022-43766stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-10-26
Advisory severity changedGHSA-9w4g-fp9h-3q2vCVE-2022-42468stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.critical2022-10-26
Advisory severity changedGHSA-rwqr-m72q-v6cmCVE-2022-42890stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-10-25
Advisory severity changedGHSA-4hjj-9gp7-4frgCVE-2022-43405stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-10-19
Advisory severity changedGHSA-7qw2-h9gj-hcvhCVE-2022-43406stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-10-19
Advisory severity changedGHSA-3f7h-mf4q-vrm4CVE-2022-40152stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.moderate2022-09-17
Advisory severity changedGHSA-fv22-xp26-mm9wCVE-2022-40153stated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.high2022-09-17
Advisory withdrawnGHSA-4rv7-wj6m-6c6rCVE-2022-40156withdrawn 2022-12-06low2022-09-17
Advisory withdrawnGHSA-5hc5-c3m9-8vcjCVE-2022-40155withdrawn 2022-12-06low2022-09-17
Advisory withdrawnGHSA-9fwf-46g9-45rxCVE-2022-40154withdrawn 2022-12-06low2022-09-17
Advisory withdrawnGHSA-fv22-xp26-mm9wCVE-2022-40153withdrawn 2022-12-06high2022-09-17
Advisory severity changedGHSA-2cpx-6pqp-wf35CVE-2022-31183stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.critical2022-07-29
Advisory severity changedGHSA-xqpp-26pp-2365CVE-2021-21660stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.moderate2022-05-24
Advisory severity changedGHSA-7ff8-qfwx-8gx5CVE-2020-2182stated at publication MODERATE, now states LOWCVSS versions were removed or replaced; no shared version's vector was rescored.low2022-05-24
Advisory withdrawnGHSA-jffq-528j-mp6cCVE-2020-10991withdrawn 2025-07-02critical2022-05-24
Advisory severity changedGHSA-682g-c99v-9r2gCVE-2019-10371stated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.high2022-05-24
Advisory severity changedGHSA-hh32-7344-cg2fCVE-2022-22978stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.critical2022-05-20
Advisory severity changedGHSA-8vfc-fcr2-47pjCVE-2022-30949stated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.low2022-05-18
Advisory severity changedGHSA-92rv-mvmj-47qhCVE-2018-1000186stated at publication MODERATE, now states LOWA CVSS version was added; the existing vectors stayed the same.low2022-05-14
Advisory withdrawnGHSA-9848-v244-962pCVE-2012-1007withdrawn 2026-05-14moderate2022-05-14
Advisory severity changedGHSA-4wrr-9h5r-m92wCVE-2012-0391stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.critical2022-05-04
Advisory severity changedGHSA-g5mm-vmx4-3rg7CVE-2022-22968stated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.high2022-04-15
Advisory severity changedGHSA-6v73-fgf6-w5j7CVE-2022-22963stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.critical2022-04-03
Advisory severity changedGHSA-cr3q-pqgq-m8c2CVE-2018-25031stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.moderate2022-03-12
Advisory severity changedGHSA-jrg3-qq99-35g7CVE-2018-21234stated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.critical2022-02-10
Advisory severity changedGHSA-wc4x-4gm2-74j8CVE-2019-10091stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.high2022-02-10
Advisory severity changedGHSA-qhh5-9738-g9mxCVE-2020-13922stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.high2022-02-09
Advisory severity changedGHSA-m6mm-q862-j366CVE-2020-1714stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.high2022-02-09
Advisory withdrawnGHSA-77rm-9x9h-xj3gCVE-2021-22570withdrawn 2025-08-25high2022-01-27
Advisory severity changedGHSA-w9p3-5cr8-m3jjCVE-2022-23302stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-01-21
Advisory severity changedGHSA-65fg-84f6-3jq3CVE-2022-23305stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.critical2022-01-21
Advisory severity changedGHSA-729f-wvj3-c4pjCVE-2020-21125stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.critical2021-09-20
Advisory severity changedGHSA-2382-qx5h-rvqhCVE-2016-11023stated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.critical2021-05-07
Advisory severity changedGHSA-f96g-24cg-f24wCVE-2016-11024stated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.critical2021-05-07
Advisory severity changedGHSA-c427-hjc3-wrfwCVE-2019-17495stated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.critical2019-10-15
Advisory severity changedGHSA-p979-4mfw-53vgCVE-2019-16869stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.high2019-10-11
Advisory severity changedGHSA-q4hg-rmq2-52q9CVE-2019-10072stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.high2019-06-26
Advisory severity changedGHSA-27xw-p8v6-9jjrCVE-2018-15801stated at publication CRITICAL, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.high2018-12-20
Advisory severity changedGHSA-hpcf-8vf9-q4gjCVE-2016-7103stated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.moderate2017-10-24

Data sources and quality

Every figure on this page counts rows keyed to a GitHub advisory, naming an ecosystem and a package. None of them counts CVE records, and none is ever added to the record counts elsewhere on this site. One row is one difference between the advisory as it was first published and the same advisory today. Rows, advisories and packages are three different numbers and are never added.

Not checked: GitHub-reviewed advisories only. An advisory GitHub never reviewed, and an ecosystem it does not review, produce no row at all, so an ecosystem missing from these figures is not evidence that its advisories held.

How advisories are compared, in full →

Advisory data from the GitHub Advisory Database, used under CC-BY-4.0. Not affiliated with or endorsed by GitHub.

Shipped snapshot computed 2026-09-07 from catalog commit 67b73cc1e9c6. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.