GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,644
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
133 advisories
Filter by severity
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
High
CVE-2026-73088
was published
for
browserslist
(npm)
Sep 1, 2026
An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld)...
High
Unreviewed
CVE-2026-81517
was published
Aug 29, 2026
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
High
CVE-2026-55484
was published
for
github.com/guno1928/alos-http
(Go)
Aug 28, 2026
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped...
High
Unreviewed
CVE-2026-82254
was published
Aug 28, 2026
Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup...
High
Unreviewed
CVE-2026-77781
was published
Aug 22, 2026
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a...
High
Unreviewed
CVE-2026-64612
was published
Jul 20, 2026
SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module...
High
Unreviewed
CVE-2025-71391
was published
Jul 18, 2026
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
High
GHSA-pfvm-w89x-94jw
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
High
CVE-2026-13697
was published
for
undici
(npm)
Aug 3, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
High
GHSA-hrxh-6v49-42gf
was published
for
google.golang.org/grpc
(Go)
Jul 21, 2026
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
High
CVE-2026-59892
was published
for
@opentelemetry/propagator-jaeger
(npm)
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
CVE-2026-61666
was published
for
websocket-driver
(RubyGems)
Jul 21, 2026
SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler...
High
Unreviewed
CVE-2026-63747
was published
Jul 20, 2026
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...
High
Unreviewed
CVE-2024-58368
was published
Jul 18, 2026
SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time()...
High
Unreviewed
CVE-2024-58357
was published
Jul 18, 2026
SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor...
High
Unreviewed
CVE-2024-58365
was published
Jul 18, 2026
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting...
High
Unreviewed
CVE-2024-58359
was published
Jul 18, 2026
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and...
High
Unreviewed
CVE-2024-58369
was published
Jul 18, 2026
SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span...
High
Unreviewed
CVE-2024-58364
was published
Jul 18, 2026
SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the...
High
Unreviewed
CVE-2024-58361
was published
Jul 18, 2026
MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
High
CVE-2025-53366
was published
for
mcp
(pip)
Jul 4, 2025
MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
High
CVE-2025-53365
was published
for
mcp
(pip)
Jul 4, 2025
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an...
High
Unreviewed
CVE-2026-47480
was published
Jul 14, 2026
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
High
CVE-2026-53530
was published
for
ratex-parser
(Rust)
Jul 7, 2026
ProTip!
Advisories are also available from the
GraphQL API