GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
433 advisories
Filter by severity
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix dead ACL conflict...
High
Unreviewed
CVE-2026-53395
was published
Jul 19, 2026
SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested...
High
Unreviewed
CVE-2024-58370
was published
Jul 18, 2026
SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when...
Moderate
Unreviewed
CVE-2025-71393
was published
Jul 18, 2026
A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers...
High
Unreviewed
CVE-2026-38755
was published
Jul 16, 2026
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows...
High
Unreviewed
CVE-2026-38752
was published
Jul 16, 2026
Protobuf: Unbounded recursion depth in embedded-message decoding
High
CVE-2026-54451
was published
for
protobuf
(Erlang)
Jul 15, 2026
Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler
Moderate
GHSA-mxwc-wh95-pw4g
was published
for
trapster
(pip)
Jul 8, 2026
ratex-parser has unbounded parser recursion that leads to stack overflow (process abort)
Moderate
CVE-2026-53531
was published
for
ratex-parser
(Rust)
Jul 7, 2026
Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the...
Moderate
Unreviewed
CVE-2026-14803
was published
Jul 6, 2026
pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu...
High
Unreviewed
CVE-2026-38970
was published
Jul 2, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
Moderate
GHSA-q8qp-67f9-wr3f
was published
for
surrealdb
(Rust)
Jul 1, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
High
GHSA-q729-696q-g9pq
was published
for
surrealdb
(Rust)
Jul 1, 2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-56148
was published
Jul 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Use...
High
Unreviewed
CVE-2026-53329
was published
Jul 1, 2026
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
High
CVE-2026-49451
was published
for
Microsoft.OpenAPI
(NuGet)
Jun 30, 2026
A flaw was found in p11-kit. The RPC message attribute parsing functions...
Moderate
Unreviewed
CVE-2026-13757
was published
Jun 29, 2026
In the Linux kernel, the following vulnerability has been resolved:
arm64: Reserve an extra page...
Moderate
Unreviewed
CVE-2026-53288
was published
Jun 26, 2026
Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)
Moderate
GHSA-6q7j-xr26-3h2c
was published
for
Scriban
(NuGet)
Jun 26, 2026
ImageMagick Vulnerable to Stack Overflow in its MVG Decoder
Moderate
CVE-2026-48734
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement
Moderate
CVE-2026-48513
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
Moderate
CVE-2026-48512
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
High
CVE-2026-48506
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
High
CVE-2026-48502
was published
for
MessagePack
(NuGet)
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_ct: bail out...
High
Unreviewed
CVE-2026-53267
was published
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
accel/ivpu: Fix signed...
High
Unreviewed
CVE-2026-53202
was published
Jun 25, 2026
ProTip!
Advisories are also available from the
GraphQL API