GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
194 advisories
Filter by severity
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust...
High
Unreviewed
CVE-2026-58067
was published
Aug 4, 2026
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length...
High
Unreviewed
CVE-2026-12852
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a...
High
Unreviewed
CVE-2026-14682
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge...
High
Unreviewed
CVE-2026-58060
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked...
High
Unreviewed
CVE-2026-59646
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by...
High
Unreviewed
CVE-2026-59649
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before...
High
Unreviewed
CVE-2026-12185
was published
Aug 3, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Moderate
CVE-2026-52857
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
High
CVE-2026-54638
was published
for
github.com/gotd/td
(Go)
Jul 28, 2026
pypdf: Possible large memory usage for wrong image dimensions
Moderate
CVE-2026-59938
was published
for
pypdf
(pip)
Jul 23, 2026
Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF...
High
Unreviewed
CVE-2026-65315
was published
Jul 22, 2026
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an...
Moderate
Unreviewed
CVE-2026-59844
was published
Jul 21, 2026
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
High
CVE-2026-59204
was published
for
pillow
(pip)
Jul 20, 2026
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
High
CVE-2026-55380
was published
for
pillow
(pip)
Jul 20, 2026
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
High
CVE-2026-55379
was published
for
pillow
(pip)
Jul 20, 2026
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
High
CVE-2026-54060
was published
for
pillow
(pip)
Jul 20, 2026
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
High
CVE-2026-54059
was published
for
pillow
(pip)
Jul 20, 2026
SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace...
High
Unreviewed
CVE-2025-71395
was published
Jul 18, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
Moderate
CVE-2026-53717
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Moderate
CVE-2026-53716
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability...
Moderate
Unreviewed
CVE-2026-58559
was published
Jul 15, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
High
CVE-2026-54448
was published
for
github.com/aquasecurity/trivy
(Go)
Jul 14, 2026
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service...
High
Unreviewed
CVE-2026-40378
was published
Jul 14, 2026
adm-zip: Crafted ZIP file triggers 4GB memory allocation
High
CVE-2026-39244
was published
for
adm-zip
(npm)
Jul 10, 2026
Tanium addressed a denial of service vulnerability in Tanium Server.
High
Unreviewed
CVE-2026-15053
was published
Jul 8, 2026
ProTip!
Advisories are also available from the
GraphQL API