GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
137 advisories
Filter by severity
Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP...
Moderate
Unreviewed
CVE-2026-18916
was published
Sep 1, 2026
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
Moderate
GHSA-2vh6-hw4j-32ww
was published
for
gix-packetline
(Rust)
Aug 28, 2026
An integer underflow was found in the DHCPv4 packet capture code of wicked....
Moderate
Unreviewed
CVE-2026-71401
was published
Aug 27, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability...
Moderate
Unreviewed
CVE-2026-76189
was published
Aug 25, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability...
Moderate
Unreviewed
CVE-2026-71444
was published
Aug 25, 2026
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component,...
Moderate
Unreviewed
CVE-2026-18728
was published
Aug 13, 2026
A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer...
Moderate
Unreviewed
CVE-2026-18727
was published
Aug 13, 2026
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an...
Moderate
Unreviewed
CVE-2026-73433
was published
Aug 12, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability...
Moderate
Unreviewed
CVE-2026-71389
was published
Aug 11, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability...
Moderate
Unreviewed
CVE-2026-48435
was published
Aug 11, 2026
Information Disclosure when processing wireless network channel switch information with...
Moderate
Unreviewed
CVE-2026-24077
was published
Aug 4, 2026
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
Moderate
CVE-2026-54345
was published
for
github.com/gopacket/gopacket
(Go)
Jul 28, 2026
[This CNA information record relates to multiple CVEs; the
text explains which aspects...
Moderate
Unreviewed
CVE-2026-42495
was published
Jul 28, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability...
Moderate
Unreviewed
CVE-2026-48298
was published
Jul 15, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability...
Moderate
Unreviewed
CVE-2026-48296
was published
Jul 15, 2026
FatFs R0.16 and earlier exhibits a stale dirty-cache skip via unsigned-subtraction wrap in f_read...
Moderate
Unreviewed
CVE-2026-6685
was published
Jul 1, 2026
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in...
Moderate
Unreviewed
CVE-2026-58058
was published
Jun 28, 2026
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Reject zero...
Moderate
Unreviewed
CVE-2026-53150
was published
Jun 25, 2026
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in...
Moderate
Unreviewed
CVE-2026-11850
was published
Jun 11, 2026
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned...
Moderate
Unreviewed
CVE-2026-11789
was published
Jun 9, 2026
In the Linux kernel, the following vulnerability has been resolved:
apparmor: avoid per-cpu hold...
Moderate
Unreviewed
CVE-2026-45884
was published
May 27, 2026
ImageMagick: Heap Buffer Over-Read in IPTC encoder
Moderate
CVE-2026-42326
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow ...
Moderate
Unreviewed
CVE-2026-34667
was published
May 12, 2026
CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow ...
Moderate
Unreviewed
CVE-2026-34672
was published
May 12, 2026
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix transaction abort...
Moderate
Unreviewed
CVE-2026-43359
was published
May 8, 2026
ProTip!
Advisories are also available from the
GraphQL API