GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,578
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
271 advisories
Filter by severity
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate...
Moderate
Unreviewed
CVE-2026-10080
was published
Aug 18, 2026
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type...
Critical
Unreviewed
CVE-2026-15826
was published
Aug 15, 2026
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could...
High
Unreviewed
CVE-2026-6726
was published
Aug 11, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Moderate
CVE-2026-73429
was published
for
russh
(Rust)
Jul 24, 2026
node-tar: Process crash via PAX numeric path type confusion
Moderate
CVE-2026-59871
was published
for
tar
(npm)
Jul 20, 2026
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to...
High
Unreviewed
CVE-2026-50337
was published
Jul 14, 2026
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
High
CVE-2026-55076
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic
High
CVE-2026-46597
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race
Moderate
CVE-2026-46690
was published
for
unbounded-spsc
(Rust)
May 29, 2026
Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer...
Moderate
Unreviewed
CVE-2023-7345
was published
May 20, 2026
OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
High
CVE-2026-45685
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)
Moderate
CVE-2026-44324
was published
for
github.com/free5gc/udr
(Go)
May 8, 2026
vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
Moderate
CVE-2026-44223
was published
for
vllm
(pip)
May 6, 2026
apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery
Moderate
CVE-2026-42576
was published
for
chainguard.dev/apko
(Go)
May 4, 2026
Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may...
Moderate
Unreviewed
CVE-2021-4456
was published
Feb 27, 2026
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the...
Critical
Unreviewed
CVE-2025-40540
was published
Feb 24, 2026
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the...
Critical
Unreviewed
CVE-2025-40539
was published
Feb 24, 2026
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited,...
Critical
Unreviewed
CVE-2025-40541
was published
Feb 24, 2026
An authorized user may disable the MongoDB server by issuing a query against a collection that...
High
Unreviewed
CVE-2026-25613
was published
Feb 10, 2026
cert-manager-controller DoS via Specially Crafted DNS Response
Moderate
CVE-2026-25518
was published
for
github.com/cert-manager/cert-manager
(Go)
Feb 2, 2026
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in...
Moderate
Unreviewed
CVE-2025-12781
was published
Jan 21, 2026
loggingredactor converts non-string types to string types in logs
Low
CVE-2026-22041
was published
for
loggingredactor
(pip)
Jan 7, 2026
Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had...
High
Unreviewed
CVE-2025-13720
was published
Dec 2, 2025
A type confusion vulnerability exists in the handling of the string addition (+) operation within...
High
Unreviewed
CVE-2025-62494
was published
Oct 16, 2025
ProTip!
Advisories are also available from the
GraphQL API