GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
136 advisories
Filter by severity
qs: Denial of Service via Attacker Controlled isBuffer
Moderate
CVE-2026-82417
was published
for
qs
(npm)
Sep 2, 2026
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
High
CVE-2026-73088
was published
for
browserslist
(npm)
Sep 1, 2026
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
High
CVE-2026-55484
was published
for
github.com/guno1928/alos-http
(Go)
Aug 28, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Moderate
CVE-2026-54553
was published
for
starlette-admin
(pip)
Aug 26, 2026
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
Moderate
GHSA-rgqc-3x5p-6gwg
was published
for
postgres-protocol
(Rust)
Aug 24, 2026
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
Moderate
CVE-2026-61799
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
asteval has a Sandbox Escape via BaseException Subclasses
Moderate
CVE-2026-55244
was published
for
asteval
(pip)
Aug 20, 2026
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
High
GHSA-pfvm-w89x-94jw
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
Moderate
CVE-2026-62909
was published
for
Microsoft.NETCore.App.Runtime.linux-arm
(NuGet)
Aug 11, 2026
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
Moderate
GHSA-3x6r-wxxg-53vv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
High
CVE-2026-13697
was published
for
undici
(npm)
Aug 3, 2026
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Moderate
CVE-2026-65834
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
SvelteKit: Big remote form function payloads can cause Node process to crash
Moderate
GHSA-wqjv-9729-c5q2
was published
for
@sveltejs/kit
(npm)
Jul 24, 2026
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
High
GHSA-hrxh-6v49-42gf
was published
for
google.golang.org/grpc
(Go)
Jul 21, 2026
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
High
CVE-2026-59892
was published
for
@opentelemetry/propagator-jaeger
(npm)
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
CVE-2026-61666
was published
for
websocket-driver
(RubyGems)
Jul 21, 2026
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
Moderate
CVE-2026-14631
was published
for
webpack-dev-server
(npm)
Jul 20, 2026
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
Moderate
CVE-2026-59875
was published
for
tar
(npm)
Jul 20, 2026
Duplicate Advisory: Uncaught Exception processing HTTP Headers in SurrealDB
High
GHSA-f7q6-7rq9-3phx
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
Duplicate Advisory: Uncaught Exception in Macro Expecting Native Function to Exist
High
GHSA-9qjc-q7hw-vw5r
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
Duplicate Advisory: SurrealDB has an Uncaught Exception Handling Nonexistent Role
Moderate
GHSA-9qrf-6whp-92w3
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes
Moderate
CVE-2026-53496
was published
for
exifreader
(npm)
Jul 17, 2026
nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys
Low
CVE-2026-54541
was published
for
nimiq-primitives
(Rust)
Jul 16, 2026
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
High
CVE-2026-53530
was published
for
ratex-parser
(Rust)
Jul 7, 2026
ProTip!
Advisories are also available from the
GraphQL API