GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
256 advisories
Filter by severity
Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data...
Moderate
Unreviewed
CVE-2026-72644
was published
Sep 1, 2026
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
High
CVE-2026-73088
was published
for
browserslist
(npm)
Sep 1, 2026
An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld)...
High
Unreviewed
CVE-2026-81517
was published
Aug 29, 2026
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
High
CVE-2026-55484
was published
for
github.com/guno1928/alos-http
(Go)
Aug 28, 2026
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped...
High
Unreviewed
CVE-2026-82254
was published
Aug 28, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Moderate
CVE-2026-54553
was published
for
starlette-admin
(pip)
Aug 26, 2026
rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation...
Moderate
Unreviewed
CVE-2026-79778
was published
Aug 25, 2026
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
Moderate
GHSA-rgqc-3x5p-6gwg
was published
for
postgres-protocol
(Rust)
Aug 24, 2026
Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup...
High
Unreviewed
CVE-2026-77781
was published
Aug 22, 2026
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
Moderate
CVE-2026-61799
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
asteval has a Sandbox Escape via BaseException Subclasses
Moderate
CVE-2026-55244
was published
for
asteval
(pip)
Aug 20, 2026
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically...
Low
Unreviewed
CVE-2026-23938
was published
Aug 18, 2026
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range...
Moderate
Unreviewed
CVE-2026-72813
was published
Aug 14, 2026
Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can...
Moderate
Unreviewed
CVE-2026-72660
was published
Aug 13, 2026
Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data...
Moderate
Unreviewed
CVE-2026-49096
was published
Aug 13, 2026
The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid...
Moderate
Unreviewed
CVE-2026-18675
was published
Aug 12, 2026
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
High
GHSA-pfvm-w89x-94jw
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
Moderate
CVE-2026-62909
was published
for
Microsoft.NETCore.App.Runtime.linux-arm
(NuGet)
Aug 11, 2026
Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain may allow a denial...
Moderate
Unreviewed
CVE-2026-20775
was published
Aug 11, 2026
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
Moderate
GHSA-3x6r-wxxg-53vv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
High
CVE-2026-13697
was published
for
undici
(npm)
Aug 3, 2026
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Moderate
CVE-2026-65834
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
SvelteKit: Big remote form function payloads can cause Node process to crash
Moderate
GHSA-wqjv-9729-c5q2
was published
for
@sveltejs/kit
(npm)
Jul 24, 2026
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
High
GHSA-hrxh-6v49-42gf
was published
for
google.golang.org/grpc
(Go)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API