GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
35 advisories
Filter by severity
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
High
CVE-2026-55771
was published
for
com.cedarpolicy:cedar-java
(Maven)
Jul 28, 2026
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
High
GHSA-2x35-3fw4-9jr4
was published
for
n8n
(npm)
Jul 22, 2026
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
High
CVE-2026-57108
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update
High
CVE-2026-52829
was published
for
zebra-network
(Rust)
Jul 2, 2026
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
High
GHSA-f4xh-w4cj-qxq8
was published
for
langsmith
(pip)
Jun 19, 2026
CedarJava has type confusion vulnerability
High
CVE-2026-55772
was published
for
com.cedarpolicy:cedar-java
(Maven)
Jun 19, 2026
containerd user ID handling bypass allows runAsNonRoot evasion
High
CVE-2026-46680
was published
for
github.com/containerd/containerd
(Go)
May 21, 2026
free5GC NRF: type-confusion panic in POST /oauth2/token structured-form parser via Reflect.Set on incompatible types
High
CVE-2026-44325
was published
for
github.com/free5gc/nrf
(Go)
May 8, 2026
@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
High
CVE-2026-44728
was published
for
@babel/plugin-transform-modules-systemjs
(npm)
May 8, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
High
CVE-2026-40683
was published
for
keystone
(pip)
Apr 14, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
High
CVE-2026-33940
was published
for
handlebars
(npm)
Mar 27, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
High
CVE-2026-33938
was published
for
handlebars
(npm)
Mar 27, 2026
Qwik City has array method pollution in FormData processing allows type confusion and DoS
High
CVE-2026-32701
was published
for
@builder.io/qwik-city
(npm)
Mar 20, 2026
PyO3 has type confusion when accessing data from sublasses of subclasses of native types with `abi3` feature
High
GHSA-47qc-857f-7w7f
was published
for
pyo3
(Rust)
Feb 19, 2026
Preact has JSON VNode Injection issue
High
CVE-2026-22028
was published
for
preact
(npm)
Jan 7, 2026
astral-tokio-tar Vulnerable to PAX Header Desynchronization
High
CVE-2025-62518
was published
for
astral-tokio-tar
(Rust)
Oct 21, 2025
try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter
High
CVE-2025-22153
was published
for
RestrictedPython
(pip)
Jan 23, 2025
TCPDF has incorrect comparison
High
CVE-2024-56522
was published
for
tecnickcom/tcpdf
(Composer)
Dec 27, 2024
eyre: Parts of Report are dropped as the wrong type during downcast
High
GHSA-4v52-7q2x-v4xj
was published
for
eyre
(Rust)
Apr 5, 2024
Duplicate advisory: Sequelize - Unsafe fall-through in getWhereConditions
High
GHSA-r3vq-92c6-3mqf
was published
for
@sequelize/core
(npm)
Feb 16, 2023
•
withdrawn
Vulnerable OpenSSL included in cryptography wheels
High
CVE-2023-0286
was published
for
cryptography
(pip)
Feb 8, 2023
Nokogiri implementation of libxslt vulnerable to heap corruption
High
CVE-2019-5815
was published
for
nokogiri
(RubyGems)
May 24, 2022
libxslt Type Confusion vulnerability that affects Nokogiri
High
CVE-2019-13118
was published
for
nokogiri
(RubyGems)
May 24, 2022
Nokogiri Improperly Handles Unexpected Data Type
High
CVE-2022-29181
was published
for
nokogiri
(RubyGems)
May 23, 2022
ChakraCore RCE Vulnerability
High
CVE-2016-7201
was published
for
Microsoft.ChakraCore
(NuGet)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API