GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
12,902 advisories
Filter by severity
An improper neutralization of special elements used in an operating system command vulnerability...
High
Unreviewed
CVE-2026-16793
was published
Aug 4, 2026
Ghost: Archived Offers can be Redeemed
Moderate
CVE-2026-70589
was published
for
ghost
(npm)
Aug 4, 2026
OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of...
Critical
Unreviewed
CVE-2026-18801
was published
Aug 4, 2026
Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized...
Moderate
Unreviewed
CVE-2026-18772
was published
Aug 4, 2026
An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of...
High
Unreviewed
CVE-2026-67978
was published
Aug 4, 2026
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
Moderate
CVE-2026-59881
was published
for
aiohttp
(pip)
Aug 3, 2026
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
High
CVE-2026-69192
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-69198
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-54272
was published
for
ip-address
(npm)
Aug 3, 2026
Socket.IO: Zero-attachment Memory Exhaustion
High
CVE-2026-69185
was published
for
socket.io-parser
(npm)
Aug 3, 2026
In modem, there is a possible improper input validation. This could lead to remote denial of...
High
Unreviewed
CVE-2026-21550
was published
Aug 3, 2026
In modem, there is a possible improper input validation. This could lead to remote denial of...
High
Unreviewed
CVE-2026-21553
was published
Aug 3, 2026
In modem, there is a possible improper input validation. This could lead to remote denial of...
High
Unreviewed
CVE-2026-21554
was published
Aug 3, 2026
In modem, there is a possible improper input validation. This could lead to remote denial of...
High
Unreviewed
CVE-2026-21551
was published
Aug 3, 2026
In modem, there is a possible improper input validation. This could lead to remote denial of...
High
Unreviewed
CVE-2026-21552
was published
Aug 3, 2026
In modem, there is a possible improper input validation. This could lead to remote denial of...
High
Unreviewed
CVE-2026-21555
was published
Aug 3, 2026
In modem, there is a possible improper input validation. This could lead to remote denial of...
High
Unreviewed
CVE-2026-21549
was published
Aug 3, 2026
In nr modem, there is a possible improper input validation. This could lead to remote denial of...
High
Unreviewed
CVE-2026-21548
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value....
Critical
Unreviewed
CVE-2026-59650
was published
Aug 3, 2026
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of...
High
Unreviewed
CVE-2025-71399
was published
Aug 2, 2026
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0...
Critical
Unreviewed
CVE-2026-67330
was published
Aug 1, 2026
GitPython before 3.1.50 fails to validate newline characters in the section parameter of...
High
Unreviewed
CVE-2026-67326
was published
Aug 1, 2026
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel...
High
Unreviewed
CVE-2026-67296
was published
Aug 1, 2026
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Moderate
CVE-2026-54909
was published
for
github.com/pion/stun
(Go)
Jul 31, 2026
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
Moderate
CVE-2026-53551
was published
for
github.com/free5gc/ausf
(Go)
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API