GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
126 advisories
Filter by severity
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
High
CVE-2026-82397
was published
for
tornado
(pip)
Sep 2, 2026
Software installed and run as a non-privileged user may conduct improper GPU system calls to pass...
High
Unreviewed
CVE-2026-45201
was published
Aug 21, 2026
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). ...
High
Unreviewed
CVE-2026-60820
was published
Aug 18, 2026
Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size...
High
Unreviewed
CVE-2026-75897
was published
Aug 18, 2026
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
High
CVE-2026-71314
was published
for
nuxt
(npm)
Aug 5, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco...
High
Unreviewed
CVE-2026-20313
was published
Aug 5, 2026
imagecli's `carve <ratio>` pipeline operation (Carve::apply() in src/image_ops.rs) only asserts ...
High
Unreviewed
CVE-2026-70378
was published
Aug 5, 2026
Improper Input Validation in the decode() function of the traceparser library could allow an...
High
Unreviewed
CVE-2026-40272
was published
Jul 29, 2026
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
High
Unreviewed
CVE-2026-59532
was published
Jul 27, 2026
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
High
Unreviewed
CVE-2026-59531
was published
Jul 27, 2026
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the...
High
Unreviewed
CVE-2026-66374
was published
Jul 25, 2026
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller...
High
Unreviewed
CVE-2026-11721
was published
Jul 22, 2026
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is...
High
Unreviewed
CVE-2026-32665
was published
Jul 22, 2026
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
High
CVE-2026-59879
was published
for
immutable
(npm)
Jul 21, 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated...
High
Unreviewed
CVE-2026-59695
was published
Jul 17, 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated...
High
Unreviewed
CVE-2026-59694
was published
Jul 17, 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated...
High
Unreviewed
CVE-2026-59252
was published
Jul 17, 2026
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
High
CVE-2026-50285
was published
for
github.com/pomerium/pomerium
(Go)
Jul 15, 2026
An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding...
High
Unreviewed
CVE-2026-57019
was published
Jul 10, 2026
An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of...
High
Unreviewed
CVE-2026-57023
was published
Jul 10, 2026
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI...
High
Unreviewed
CVE-2022-4990
was published
Jul 3, 2026
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI...
High
Unreviewed
CVE-2022-4989
was published
Jul 3, 2026
Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.
High
Unreviewed
CVE-2026-56035
was published
Jun 26, 2026
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
High
CVE-2026-39829
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
spomky-labs/otphp: Unbounded digits parameter in a provisioning URI triggers an uncaught DivisionByZeroError in OTP generation
High
GHSA-g7m4-839x-ch6v
was published
for
spomky-labs/otphp
(Composer)
Jun 18, 2026
ProTip!
Advisories are also available from the
GraphQL API