GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
308 advisories
Filter by severity
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request:...
High
Unreviewed
CVE-2026-66754
was published
Jul 28, 2026
Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple...
High
Unreviewed
CVE-2026-45815
was published
Jul 24, 2026
During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t...
High
Unreviewed
CVE-2026-9737
was published
Jul 22, 2026
An authenticated user with basic write privileges can cause the mongod process to terminate...
High
Unreviewed
CVE-2026-13058
was published
Jul 22, 2026
The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a...
High
Unreviewed
CVE-2026-13055
was published
Jul 22, 2026
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and...
High
Unreviewed
CVE-2026-13204
was published
Jul 22, 2026
The issue is unexpected program termination based on ordering and/or specific content in...
High
Unreviewed
CVE-2026-12617
was published
Jul 22, 2026
vLLM denial of service via prompt embeds on M-RoPE models
High
CVE-2026-55514
was published
for
vllm
(pip)
Jul 20, 2026
In the Linux kernel, the following vulnerability has been resolved:
KVM: Replace guest...
High
Unreviewed
CVE-2026-63806
was published
Jul 19, 2026
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in...
High
Unreviewed
CVE-2025-56365
was published
Jul 15, 2026
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2,...
High
Unreviewed
CVE-2025-56362
was published
Jul 15, 2026
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4,...
High
Unreviewed
CVE-2025-56361
was published
Jul 15, 2026
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update
High
CVE-2026-52829
was published
for
zebra-network
(Rust)
Jul 2, 2026
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that...
High
Unreviewed
CVE-2026-47146
was published
Jun 25, 2026
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that...
High
Unreviewed
CVE-2026-47145
was published
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
iommu: Fix WARN_ON in...
High
Unreviewed
CVE-2026-52952
was published
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
libceph: handle rbtree...
High
Unreviewed
CVE-2026-52954
was published
Jun 24, 2026
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
High
CVE-2026-41523
was published
for
vllm
(pip)
Jun 16, 2026
A vulnerability has been found in some Dahua products could
allow an unauthenticated remote...
High
Unreviewed
CVE-2026-29116
was published
Jun 10, 2026
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb...
High
Unreviewed
CVE-2026-9747
was published
Jun 10, 2026
This issue can occur when running an aggregation pipeline that uses the internal $exchange stage...
High
Unreviewed
CVE-2026-9749
was published
Jun 10, 2026
When using $changestreams and $_requestReshardingResumeToken with the exchange option the server...
High
Unreviewed
CVE-2026-9746
was published
Jun 10, 2026
The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this...
High
Unreviewed
CVE-2026-9748
was published
Jun 10, 2026
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating...
High
Unreviewed
CVE-2026-9750
was published
Jun 10, 2026
ProTip!
Advisories are also available from the
GraphQL API