GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
69
GitHub Actions
50
Go
3,876
Maven
5,000+
npm
5,000+
NuGet
958
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,363
Swift
54
Unreviewed advisories
All unreviewed
5,000+
92 advisories
Filter by severity
ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.
Moderate
CVE-2026-45624
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define
Moderate
CVE-2026-45359
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to...
Moderate
Unreviewed
CVE-2023-31309
was published
May 15, 2026
gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
Moderate
CVE-2026-44310
was published
for
github.com/sigstore/gitsign
(Go)
May 8, 2026
vLLM Vulnerable to Remote DoS via Special-Token Placeholders
Moderate
CVE-2026-44222
was published
for
vllm
(pip)
May 5, 2026
Missing bounds validation for operator could allow out of range operator-code lookup during...
Moderate
Unreviewed
CVE-2026-6840
was published
Apr 22, 2026
Wasmtime: Panic when transcoding misaligned utf-16 strings
Moderate
CVE-2026-34942
was published
for
wasmtime
(Rust)
Apr 9, 2026
Packetbeat does not properly validate an array index in multiple protocol parser components
Moderate
CVE-2026-26933
was published
for
github.com/elastic/beats/v7
(Go)
Mar 19, 2026
Ella Core panics on invalid PDU Session IDs in NGAP messages
Moderate
CVE-2026-33281
was published
for
github.com/ellanetworks/core
(Go)
Mar 19, 2026
Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun
Moderate
CVE-2026-33022
was published
for
github.com/tektoncd/pipeline
(Go)
Mar 17, 2026
Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can...
Moderate
Unreviewed
CVE-2026-26932
was published
Feb 26, 2026
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow
Moderate
CVE-2026-25882
was published
for
github.com/gofiber/fiber/v2
(Go)
Feb 24, 2026
Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds...
Moderate
Unreviewed
CVE-2023-20601
was published
Feb 12, 2026
cert-manager-controller DoS via Specially Crafted DNS Response
Moderate
CVE-2026-25518
was published
for
github.com/cert-manager/cert-manager
(Go)
Feb 2, 2026
alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap...
Moderate
Unreviewed
CVE-2026-25068
was published
Jan 29, 2026
Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an...
Moderate
Unreviewed
CVE-2026-0529
was published
Jan 14, 2026
Metricbeat affected by multiple denial of service vulnerabilities
Moderate
CVE-2026-0528
was published
for
github.com/elastic/beats/v7
(Go)
Jan 13, 2026
Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows...
Moderate
Unreviewed
CVE-2025-65499
was published
Nov 24, 2025
A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds...
Moderate
Unreviewed
CVE-2025-10158
was published
Nov 18, 2025
Improper validation of an array index in the AND power Management Firmware could allow a...
Moderate
Unreviewed
CVE-2024-21970
was published
Sep 6, 2025
Improper array index verification vulnerability in the audio codec module.
Impact: Successful...
Moderate
Unreviewed
CVE-2025-54650
was published
Aug 6, 2025
Out-of-bounds array access issue due to insufficient data verification in the location service...
Moderate
Unreviewed
CVE-2025-54645
was published
Aug 6, 2025
Out-of-bounds access vulnerability in the audio codec module.
Impact: Successful exploitation of...
Moderate
Unreviewed
CVE-2025-54610
was published
Aug 6, 2025
Memory corruption while operating the mailbox in Automotive.
Moderate
Unreviewed
CVE-2024-53009
was published
Jul 8, 2025
The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console...
Moderate
Unreviewed
CVE-2024-35164
was published
Jul 2, 2025
ProTip!
Advisories are also available from the
GraphQL API