GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
158 advisories
Filter by severity
API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
Moderate
CVE-2026-54164
was published
for
api-platform/core
(Composer)
Aug 7, 2026
Type Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote...
Moderate
Unreviewed
CVE-2026-17866
was published
Jul 30, 2026
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.6 and...
Moderate
Unreviewed
CVE-2026-64693
was published
Jul 27, 2026
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized...
Moderate
Unreviewed
CVE-2026-54116
was published
Jul 14, 2026
Access of resource using incompatible type ('type confusion') in Composite Image File System...
Moderate
Unreviewed
CVE-2026-50381
was published
Jul 14, 2026
Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open...
Moderate
Unreviewed
CVE-2026-58305
was published
Jul 9, 2026
async-tar PAX extension-header desync enables tar entry/content smuggling
Moderate
CVE-2026-53600
was published
for
async-tar
(Rust)
Jul 8, 2026
Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain...
Moderate
Unreviewed
CVE-2026-14148
was published
Jul 1, 2026
Type Confusion in Bluetooth in Google Chrome on Windows prior to 150.0.7871.47 allowed an...
Moderate
Unreviewed
CVE-2026-14119
was published
Jul 1, 2026
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox...
Moderate
Unreviewed
CVE-2026-12298
was published
Jun 16, 2026
JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152...
Moderate
Unreviewed
CVE-2026-12299
was published
Jun 16, 2026
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation...
Moderate
Unreviewed
CVE-2026-11785
was published
Jun 9, 2026
The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via...
Moderate
Unreviewed
CVE-2026-8499
was published
Jun 9, 2026
Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain...
Moderate
Unreviewed
CVE-2026-11196
was published
Jun 5, 2026
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet...
Moderate
Unreviewed
CVE-2026-48682
was published
Jun 2, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in...
Moderate
Unreviewed
CVE-2026-10702
was published
Jun 2, 2026
tar has a PAX header desynchronization issue
Moderate
GHSA-3pv8-6f4r-ffg2
was published
for
tar
(Rust)
May 29, 2026
astral-tokio-tar has a PAX Header Desynchronization issue
Moderate
GHSA-3cv2-h65g-fgmm
was published
for
astral-tokio-tar
(Rust)
May 29, 2026
Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain...
Moderate
Unreviewed
CVE-2026-8570
was published
May 14, 2026
TanStack Start - Server Core: Inbound server-function request deserialization could invoke a sibling client-referenced server function
Moderate
GHSA-9m65-766c-r333
was published
for
@tanstack/start-server-core
(npm)
May 14, 2026
astral-tokio-tar is Vulnerable to PAX Header Desynchronization
Moderate
GHSA-fp55-jw48-c537
was published
for
astral-tokio-tar
(Rust)
May 6, 2026
In slbc, there is a possible out of bounds write due to type confusion. This could lead to local...
Moderate
Unreviewed
CVE-2026-20451
was published
May 4, 2026
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially...
Moderate
Unreviewed
CVE-2026-6732
was published
Apr 24, 2026
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized...
Moderate
Unreviewed
CVE-2026-20806
was published
Apr 14, 2026
Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open...
Moderate
Unreviewed
CVE-2026-40446
was published
Apr 13, 2026
ProTip!
Advisories are also available from the
GraphQL API