GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
727 advisories
Filter by severity
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
Moderate
CVE-2026-71430
was published
for
re2
(npm)
Aug 6, 2026
A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some...
Low
Unreviewed
CVE-2026-18581
was published
Aug 3, 2026
FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength ==...
Moderate
Unreviewed
CVE-2026-67303
was published
Aug 1, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request:...
High
Unreviewed
CVE-2026-66754
was published
Jul 28, 2026
A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function...
Low
Unreviewed
CVE-2026-17513
was published
Jul 27, 2026
Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple...
High
Unreviewed
CVE-2026-45815
was published
Jul 24, 2026
During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t...
High
Unreviewed
CVE-2026-9737
was published
Jul 22, 2026
An authenticated user with read-only privileges can cause the mongod process to terminate...
Moderate
Unreviewed
CVE-2026-13073
was published
Jul 22, 2026
An authenticated user with basic write privileges can cause the mongod process to terminate...
High
Unreviewed
CVE-2026-13058
was published
Jul 22, 2026
The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a...
High
Unreviewed
CVE-2026-13055
was published
Jul 22, 2026
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and...
High
Unreviewed
CVE-2026-13204
was published
Jul 22, 2026
The issue is unexpected program termination based on ordering and/or specific content in...
High
Unreviewed
CVE-2026-12617
was published
Jul 22, 2026
If BIND encounters a particular invalid data structure in a DNS record, it will accept the...
Moderate
Unreviewed
CVE-2026-10822
was published
Jul 22, 2026
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high...
Moderate
Unreviewed
CVE-2026-14586
was published
Jul 22, 2026
Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data...
Moderate
Unreviewed
CVE-2026-63140
was published
Jul 21, 2026
vLLM denial of service via prompt embeds on M-RoPE models
High
CVE-2026-55514
was published
for
vllm
(pip)
Jul 20, 2026
In the Linux kernel, the following vulnerability has been resolved:
KVM: Replace guest...
High
Unreviewed
CVE-2026-63806
was published
Jul 19, 2026
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in...
High
Unreviewed
CVE-2025-56365
was published
Jul 15, 2026
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2,...
High
Unreviewed
CVE-2025-56362
was published
Jul 15, 2026
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4,...
High
Unreviewed
CVE-2025-56361
was published
Jul 15, 2026
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an...
Moderate
Unreviewed
CVE-2026-47475
was published
Jul 14, 2026
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to...
Moderate
Unreviewed
CVE-2026-13122
was published
Jul 6, 2026
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update
High
CVE-2026-52829
was published
for
zebra-network
(Rust)
Jul 2, 2026
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers
Moderate
GHSA-c8w6-x74f-vmg3
was published
for
zebra-rpc
(Rust)
Jul 2, 2026
ProTip!
Advisories are also available from the
GraphQL API