Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12,902 advisories

Loading
Ghost: Archived Offers can be Redeemed Moderate
CVE-2026-70589 was published for ghost (npm) Aug 4, 2026
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate Moderate
CVE-2026-59881 was published for aiohttp (pip) Aug 3, 2026
gik2927 Credited to gik2927 and Dreamsorcerer Dreamsorcerer Dreamsorcerer
hi-im-glitchless Credited to hi-im-glitchless
OV-0-VO Credited to OV-0-VO
Socket.IO: Zero-attachment Memory Exhaustion High
CVE-2026-69185 was published for socket.io-parser (npm) Aug 3, 2026
aretekzs Credited to aretekzs, mauriceng98, Zyy0530, Str1ckl4nd, and 7thParkk mauriceng98 mauriceng98
Zyy0530 Zyy0530 Str1ckl4nd Str1ckl4nd 7thParkk 7thParkk
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute Moderate
CVE-2026-54909 was published for github.com/pion/stun (Go) Jul 31, 2026
kajaaz Credited to kajaaz and Sean-Der Sean-Der Sean-Der
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure Moderate
CVE-2026-53551 was published for github.com/free5gc/ausf (Go) Jul 31, 2026
ProTip! Advisories are also available from the GraphQL API