GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,675
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
113 advisories
Filter by severity
qs: Denial of Service via Attacker Controlled isBuffer
Moderate
CVE-2026-82417
was published
for
qs
(npm)
Sep 2, 2026
Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data...
Moderate
Unreviewed
CVE-2026-72644
was published
Sep 1, 2026
Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain may allow a denial...
Moderate
Unreviewed
CVE-2026-20775
was published
Aug 11, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Moderate
CVE-2026-54553
was published
for
starlette-admin
(pip)
Aug 26, 2026
rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation...
Moderate
Unreviewed
CVE-2026-79778
was published
Aug 25, 2026
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
Moderate
GHSA-rgqc-3x5p-6gwg
was published
for
postgres-protocol
(Rust)
Aug 24, 2026
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
Moderate
CVE-2026-61799
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
asteval has a Sandbox Escape via BaseException Subclasses
Moderate
CVE-2026-55244
was published
for
asteval
(pip)
Aug 20, 2026
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range...
Moderate
Unreviewed
CVE-2026-72813
was published
Aug 14, 2026
Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can...
Moderate
Unreviewed
CVE-2026-72660
was published
Aug 13, 2026
Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data...
Moderate
Unreviewed
CVE-2026-49096
was published
Aug 13, 2026
The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid...
Moderate
Unreviewed
CVE-2026-18675
was published
Aug 12, 2026
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
Moderate
CVE-2026-62909
was published
for
Microsoft.NETCore.App.Runtime.linux-arm
(NuGet)
Aug 11, 2026
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
Moderate
GHSA-3x6r-wxxg-53vv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Moderate
CVE-2026-65834
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
SvelteKit: Big remote form function payloads can cause Node process to crash
Moderate
GHSA-wqjv-9729-c5q2
was published
for
@sveltejs/kit
(npm)
Jul 24, 2026
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
Moderate
CVE-2026-14631
was published
for
webpack-dev-server
(npm)
Jul 20, 2026
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
Moderate
CVE-2026-59875
was published
for
tar
(npm)
Jul 20, 2026
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that...
Moderate
Unreviewed
CVE-2024-58358
was published
Jul 18, 2026
ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes
Moderate
CVE-2026-53496
was published
for
exifreader
(npm)
Jul 17, 2026
Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection
Moderate
CVE-2026-52739
was published
for
zebra-state
(Rust)
Jul 2, 2026
Zebra: Finalized address balance credit-first overflow on consensus-valid blocks
Moderate
CVE-2026-52738
was published
for
zebra-state
(Rust)
Jul 2, 2026
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers
Moderate
GHSA-c8w6-x74f-vmg3
was published
for
zebra-rpc
(Rust)
Jul 2, 2026
zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplate
Moderate
CVE-2026-52731
was published
for
zebra-rpc
(Rust)
Jul 2, 2026
ts-deepmerge: Prototype Method Override leads to DoS
Moderate
CVE-2026-12644
was published
for
ts-deepmerge
(npm)
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API