GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
5,744 advisories
Filter by severity
Ghost: Archived Offers can be Redeemed
Moderate
CVE-2026-70589
was published
for
ghost
(npm)
Aug 4, 2026
Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized...
Moderate
Unreviewed
CVE-2026-18772
was published
Aug 4, 2026
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
Moderate
CVE-2026-59881
was published
for
aiohttp
(pip)
Aug 3, 2026
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-69198
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-54272
was published
for
ip-address
(npm)
Aug 3, 2026
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Moderate
CVE-2026-54909
was published
for
github.com/pion/stun
(Go)
Jul 31, 2026
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
Moderate
CVE-2026-53551
was published
for
github.com/free5gc/ausf
(Go)
Jul 31, 2026
HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to...
Moderate
Unreviewed
CVE-2025-62347
was published
Jul 31, 2026
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Moderate
CVE-2026-65834
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
A flaw was found in the secure-client-uris client policy executor within Keycloak core services....
Moderate
Unreviewed
CVE-2026-18211
was published
Jul 31, 2026
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-18009
was published
Jul 30, 2026
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-18014
was published
Jul 30, 2026
Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17982
was published
Jul 30, 2026
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17988
was published
Jul 30, 2026
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17970
was published
Jul 30, 2026
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17926
was published
Jul 30, 2026
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17929
was published
Jul 30, 2026
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17934
was published
Jul 30, 2026
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17937
was published
Jul 30, 2026
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17939
was published
Jul 30, 2026
Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17955
was published
Jul 30, 2026
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17921
was published
Jul 30, 2026
Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922...
Moderate
Unreviewed
CVE-2026-17893
was published
Jul 30, 2026
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17890
was published
Jul 30, 2026
Insufficient validation of untrusted input in Sharing in Google Chrome on Android prior to 151.0...
Moderate
Unreviewed
CVE-2026-17901
was published
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API