GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
30 advisories
Filter by severity
API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
Moderate
CVE-2026-54164
was published
for
api-platform/core
(Composer)
Aug 7, 2026
async-tar PAX extension-header desync enables tar entry/content smuggling
Moderate
CVE-2026-53600
was published
for
async-tar
(Rust)
Jul 8, 2026
tar has a PAX header desynchronization issue
Moderate
GHSA-3pv8-6f4r-ffg2
was published
for
tar
(Rust)
May 29, 2026
astral-tokio-tar has a PAX Header Desynchronization issue
Moderate
GHSA-3cv2-h65g-fgmm
was published
for
astral-tokio-tar
(Rust)
May 29, 2026
tar-rs incorrectly ignores PAX size headers if header size is nonzero
Moderate
CVE-2026-33055
was published
for
tar
(Rust)
Mar 20, 2026
TanStack Start - Server Core: Inbound server-function request deserialization could invoke a sibling client-referenced server function
Moderate
GHSA-9m65-766c-r333
was published
for
@tanstack/start-server-core
(npm)
May 14, 2026
astral-tokio-tar is Vulnerable to PAX Header Desynchronization
Moderate
GHSA-fp55-jw48-c537
was published
for
astral-tokio-tar
(Rust)
May 6, 2026
Roundcube Webmail: Incorrect password comparison in the password plugin
Moderate
CVE-2026-35541
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
DynFuture Drop Can Construct a Dangling Reference
Moderate
GHSA-j3w3-p6mr-3hrh
was published
for
dyn-future
(Rust)
Apr 4, 2026
Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value
Moderate
CVE-2026-34595
was published
for
parse-server
(npm)
Apr 1, 2026
CPU exhaustion in SvelteKit remote form deserialization (experimental only)
Moderate
GHSA-88qp-p4qg-rqm6
was published
for
@sveltejs/kit
(npm)
Feb 19, 2026
jsonwebtoken has Type Confusion that leads to potential authorization bypass
Moderate
CVE-2026-25537
was published
for
jsonwebtoken
(Rust)
Feb 3, 2026
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
Moderate
CVE-2025-61911
was published
for
python-ldap
(pip)
Oct 10, 2025
@digitalocean/do-markdownit has Type Confusion vulnerability
Moderate
CVE-2025-59717
was published
for
@digitalocean/do-markdownit
(npm)
Sep 19, 2025
Prototype Pollution in node-jsonpointer
Moderate
CVE-2021-23807
was published
for
jsonpointer
(npm)
Nov 8, 2021
Undefined behaviour in `kvm_ioctls::ioctls::vm::VmFd::create_device`
Moderate
GHSA-3qx8-rv27-j6gp
was published
for
kvm-ioctls
(Rust)
Dec 23, 2024
Jenkins item creation restriction bypass vulnerability
Moderate
CVE-2024-47804
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Oct 2, 2024
Wrong type for `Linker`-define functions when used across two `Engine`s
Moderate
CVE-2021-39219
was published
for
wasmtime
(pip)
Sep 20, 2021
`CHECK`-failures in binary ops in Tensorflow
Moderate
CVE-2022-23583
was published
for
tensorflow
(pip)
Feb 10, 2022
Cross-site Scripting in edge.js
Moderate
CVE-2021-23443
was published
for
edge.js
(npm)
Sep 22, 2021
Prototype Pollution in object-path
Moderate
CVE-2021-23434
was published
for
object-path
(npm)
Sep 1, 2021
Prototype Pollution in json-ptr
Moderate
CVE-2021-23509
was published
for
json-ptr
(npm)
Nov 8, 2021
ProTip!
Advisories are also available from the
GraphQL API