GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,578
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
45 advisories
Filter by severity
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate...
Moderate
Unreviewed
CVE-2026-10080
was published
Aug 18, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Moderate
CVE-2026-73429
was published
for
russh
(Rust)
Jul 24, 2026
node-tar: Process crash via PAX numeric path type confusion
Moderate
CVE-2026-59871
was published
for
tar
(npm)
Jul 20, 2026
unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race
Moderate
CVE-2026-46690
was published
for
unbounded-spsc
(Rust)
May 29, 2026
Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer...
Moderate
Unreviewed
CVE-2023-7345
was published
May 20, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)
Moderate
CVE-2026-44324
was published
for
github.com/free5gc/udr
(Go)
May 8, 2026
vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
Moderate
CVE-2026-44223
was published
for
vllm
(pip)
May 6, 2026
apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery
Moderate
CVE-2026-42576
was published
for
chainguard.dev/apko
(Go)
May 4, 2026
Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may...
Moderate
Unreviewed
CVE-2021-4456
was published
Feb 27, 2026
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
cert-manager-controller DoS via Specially Crafted DNS Response
Moderate
CVE-2026-25518
was published
for
github.com/cert-manager/cert-manager
(Go)
Feb 2, 2026
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in...
Moderate
Unreviewed
CVE-2025-12781
was published
Jan 21, 2026
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix wrong reg type...
Moderate
Unreviewed
CVE-2022-49873
was published
May 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
perf/dwc_pcie: fix duplicate...
Moderate
Unreviewed
CVE-2025-37746
was published
May 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
acpi: nfit: fix narrowing...
Moderate
Unreviewed
CVE-2025-22044
was published
Apr 16, 2025
Keylime registrar is vulnerable to Denial-of-Service attack when updated to version 7.12.0
Moderate
CVE-2025-1057
was published
for
keylime
(pip)
Feb 14, 2025
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an...
Moderate
Unreviewed
CVE-2025-20072
was published
Jan 16, 2025
Mattermost Incorrect Type Conversion or Cast
Moderate
CVE-2025-21088
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
In the Linux kernel, the following vulnerability has been resolved:
Revert "readahead: properly...
Moderate
Unreviewed
CVE-2024-57839
was published
Jan 11, 2025
OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter...
Moderate
Unreviewed
CVE-2024-36735
was published
Jun 6, 2024
transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.
Moderate
Unreviewed
CVE-2024-21478
was published
Jun 3, 2024
Invalid char to bool conversion when printing a tensor
Moderate
CVE-2022-41911
was published
for
tensorflow
(pip)
Nov 21, 2022
`CHECK` fail in `BCast` overflow
Moderate
CVE-2022-41890
was published
for
tensorflow
(pip)
Nov 21, 2022
In audio DSP, there is a possible memory corruption due to improper casting. This could lead to...
Moderate
Unreviewed
CVE-2022-21786
was published
Jul 7, 2022
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A NULL pointer...
Moderate
Unreviewed
CVE-2021-25177
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API