GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
166 advisories
Filter by severity
Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU...
Moderate
Unreviewed
CVE-2026-45202
was published
Aug 21, 2026
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed...
Moderate
Unreviewed
CVE-2026-18663
was published
Aug 12, 2026
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file...
Moderate
Unreviewed
CVE-2026-17573
was published
Jul 27, 2026
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor...
Moderate
Unreviewed
CVE-2026-13713
was published
Jul 17, 2026
A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the...
Moderate
Unreviewed
CVE-2026-58381
was published
Jul 2, 2026
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26...
Moderate
Unreviewed
CVE-2026-43706
was published
Jun 29, 2026
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in...
Moderate
Unreviewed
CVE-2026-55653
was published
Jun 23, 2026
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering
a crafted response...
Moderate
Unreviewed
CVE-2026-35188
was published
Jun 9, 2026
unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race
Moderate
CVE-2026-46690
was published
for
unbounded-spsc
(Rust)
May 29, 2026
rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution
Moderate
GHSA-vfvv-c25p-m7mm
was published
for
rkyv
(Rust)
May 15, 2026
Double free in Windows Rich Text Edit Control allows an authorized attacker to elevate privileges...
Moderate
Unreviewed
CVE-2026-32170
was published
May 12, 2026
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
Moderate
Unreviewed
CVE-2026-21530
was published
May 12, 2026
iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Moderate
Unreviewed
CVE-2026-5657
was published
Apr 30, 2026
Double free vulnerability in the multi-mode input system.
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2026-34867
was published
Apr 13, 2026
A double free vulnerability exists in librz/bin/format/le/le.c in the function...
Moderate
Unreviewed
CVE-2026-31053
was published
Apr 6, 2026
A specially crafted aggregation query with $lookup by an authenticated user with write privileges...
Moderate
Unreviewed
CVE-2026-4358
was published
Mar 17, 2026
Giflib contains a double-free vulnerability that is the result of a shallow copy in...
Moderate
Unreviewed
CVE-2026-23868
was published
Mar 10, 2026
Double free vulnerability in the window module. Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2026-28537
was published
Mar 5, 2026
Hive has Double-free and Use After Free Vulnerabilities
Moderate
GHSA-j8cj-hw74-64jv
was published
for
hivex
(Rust)
Feb 28, 2026
libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
Moderate
Unreviewed
CVE-2025-61145
was published
Feb 23, 2026
MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in...
Moderate
Unreviewed
CVE-2026-25556
was published
Feb 6, 2026
In imgsys, there is a possible memory corruption due to improper locking. This could lead to...
Moderate
Unreviewed
CVE-2026-20415
was published
Feb 2, 2026
A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which...
Moderate
Unreviewed
CVE-2025-57785
was published
Jan 26, 2026
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC...
Moderate
Unreviewed
CVE-2026-20026
was published
Jan 7, 2026
In display, there is a possible memory corruption due to use after free. This could lead to local...
Moderate
Unreviewed
CVE-2025-20786
was published
Jan 6, 2026
ProTip!
Advisories are also available from the
GraphQL API