GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
151 advisories
Filter by severity
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
High
CVE-2026-69244
was published
for
aiohttp
(pip)
Aug 3, 2026
MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
High
GHSA-6v7p-g79w-8964
was published
for
msgpack
(pip)
Jun 19, 2026
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
Low
GHSA-wjv4-x9w8-wm3h
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
CVE-2026-54522
was published
for
msgpack
(RubyGems)
Jul 30, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
CVE-2026-54620
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
CVE-2026-54619
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails
Low
GHSA-qvxh-prvr-85w2
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Use-After-Free when freetype initialization fails
Low
GHSA-6jwg-7q3p-5fqm
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
Low
GHSA-qh5g-q395-cx4j
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Use-After-Free in crafted 8BIM when identifying an image
Moderate
CVE-2026-55510
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
Moderate
GHSA-ggxf-9f6j-w742
was published
for
diesel
(Rust)
Jul 16, 2026
OneRingBuf has a Use After Free Vulnerability
Moderate
GHSA-q95x-7g78-rccv
was published
for
oneringbuf
(Rust)
Jul 8, 2026
Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule
Low
CVE-2025-10994
was published
for
openbabel
(pip)
Jun 30, 2026
ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails
Moderate
CVE-2026-53462
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 26, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
Moderate
CVE-2026-11941
was published
for
quiche
(Rust)
Jun 19, 2026
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
High
CVE-2026-54902
was published
for
oj
(RubyGems)
Jun 19, 2026
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
High
CVE-2026-54901
was published
for
oj
(RubyGems)
Jun 19, 2026
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
High
CVE-2026-54900
was published
for
oj
(RubyGems)
Jun 19, 2026
Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
High
CVE-2026-54898
was published
for
oj
(RubyGems)
Jun 19, 2026
Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
High
CVE-2026-54897
was published
for
oj
(RubyGems)
Jun 19, 2026
Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
High
CVE-2026-54899
was published
for
oj
(RubyGems)
Jun 19, 2026
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
Low
GHSA-phwj-rprq-35pp
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: Possible Use-After-Free in XInclude Processing
Low
GHSA-wfpw-mmfh-qq69
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
Low
GHSA-p67v-3w7g-wjg7
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
Low
GHSA-5v8h-3h3q-446p
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API