GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
731 advisories
Filter by severity
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through...
Moderate
Unreviewed
CVE-2026-35058
was published
Jun 8, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: txgbe: fix RTNL...
Moderate
Unreviewed
CVE-2026-46287
was published
Jun 8, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Low
CVE-2026-10300
was published
for
sglang
(pip)
Jun 2, 2026
FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The...
High
Unreviewed
CVE-2026-37228
was published
Jun 1, 2026
FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER...
High
Unreviewed
CVE-2026-37229
was published
Jun 1, 2026
FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The...
High
Unreviewed
CVE-2026-37233
was published
Jun 1, 2026
FlexRIC v2.0.0 contains a reachable assertion in the iApp message dispatcher. The dispatcher...
High
Unreviewed
CVE-2026-37223
was published
Jun 1, 2026
FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST with an empty...
High
Unreviewed
CVE-2026-37225
was published
Jun 1, 2026
FlexRIC v2.0.0 crashes when receiving a duplicate E2_SETUP_REQUEST from the same or spoofed E2...
High
Unreviewed
CVE-2026-37224
was published
Jun 1, 2026
FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but...
High
Unreviewed
CVE-2026-37227
was published
Jun 1, 2026
FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded...
High
Unreviewed
CVE-2026-37222
was published
Jun 1, 2026
FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The...
High
Unreviewed
CVE-2026-37220
was published
Jun 1, 2026
FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has...
High
Unreviewed
CVE-2026-37221
was published
Jun 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma4: replace...
Moderate
Unreviewed
CVE-2026-46220
was published
May 28, 2026
In the Linux kernel, the following vulnerability has been resolved:
RDMA/mana: Remove user...
High
Unreviewed
CVE-2026-46117
was published
May 28, 2026
A vulnerability was detected in TeamSpeak 3 Server up to 3.13.7. This issue affects some unknown...
Moderate
Unreviewed
CVE-2026-4392
was published
May 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: remove WARN_ON_ONCE...
Moderate
Unreviewed
CVE-2026-45847
was published
May 27, 2026
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module...
Moderate
Unreviewed
CVE-2026-8852
was published
May 26, 2026
PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
Low
Unreviewed
CVE-2026-48852
was published
May 26, 2026
A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function...
Low
Unreviewed
CVE-2026-9501
was published
May 26, 2026
nimiq-blockchain: Genesis batch set request
Moderate
CVE-2026-46543
was published
for
nimiq-blockchain
(Rust)
May 21, 2026
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
Moderate
CVE-2026-46542
was published
for
nimiq-keys
(Rust)
May 21, 2026
Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES
command within a transaction...
Moderate
Unreviewed
CVE-2026-23557
was published
May 19, 2026
Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any...
High
Unreviewed
CVE-2026-8843
was published
May 18, 2026
A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function...
Low
Unreviewed
CVE-2026-8257
was published
May 11, 2026
ProTip!
Advisories are also available from the
GraphQL API