GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
397 advisories
Filter by severity
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
Moderate
CVE-2026-71430
was published
for
re2
(npm)
Aug 6, 2026
FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength ==...
Moderate
Unreviewed
CVE-2026-67303
was published
Aug 1, 2026
An authenticated user with read-only privileges can cause the mongod process to terminate...
Moderate
Unreviewed
CVE-2026-13073
was published
Jul 22, 2026
If BIND encounters a particular invalid data structure in a DNS record, it will accept the...
Moderate
Unreviewed
CVE-2026-10822
was published
Jul 22, 2026
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high...
Moderate
Unreviewed
CVE-2026-14586
was published
Jul 22, 2026
Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data...
Moderate
Unreviewed
CVE-2026-63140
was published
Jul 21, 2026
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an...
Moderate
Unreviewed
CVE-2026-47475
was published
Jul 14, 2026
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to...
Moderate
Unreviewed
CVE-2026-13122
was published
Jul 6, 2026
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers
Moderate
GHSA-c8w6-x74f-vmg3
was published
for
zebra-rpc
(Rust)
Jul 2, 2026
In the Linux kernel, the following vulnerability has been resolved:
blk-wbt: remove WARN_ON_ONCE...
Moderate
Unreviewed
CVE-2026-53319
was published
Jun 26, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: phonet: do not BUG_ON()...
Moderate
Unreviewed
CVE-2026-53292
was published
Jun 26, 2026
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Wrap DCN32...
Moderate
Unreviewed
CVE-2026-53285
was published
Jun 26, 2026
CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to...
Moderate
Unreviewed
CVE-2026-9718
was published
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
accel/ethosu: reject...
Moderate
Unreviewed
CVE-2026-53169
was published
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: validate group add...
Moderate
Unreviewed
CVE-2026-53039
was published
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix BUG_ON in...
Moderate
Unreviewed
CVE-2026-52961
was published
Jun 24, 2026
OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types
Moderate
CVE-2026-55776
was published
for
github.com/openbao/openbao
(Go)
Jun 19, 2026
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad....
Moderate
Unreviewed
CVE-2026-52718
was published
Jun 15, 2026
A vulnerability has been found in some Dahua products could allow an authenticated remote...
Moderate
Unreviewed
CVE-2026-29115
was published
Jun 10, 2026
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through...
Moderate
Unreviewed
CVE-2026-35058
was published
Jun 8, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: txgbe: fix RTNL...
Moderate
Unreviewed
CVE-2026-46287
was published
Jun 8, 2026
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma4: replace...
Moderate
Unreviewed
CVE-2026-46220
was published
May 28, 2026
A vulnerability was detected in TeamSpeak 3 Server up to 3.13.7. This issue affects some unknown...
Moderate
Unreviewed
CVE-2026-4392
was published
May 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: remove WARN_ON_ONCE...
Moderate
Unreviewed
CVE-2026-45847
was published
May 27, 2026
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module...
Moderate
Unreviewed
CVE-2026-8852
was published
May 26, 2026
ProTip!
Advisories are also available from the
GraphQL API