GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,755
Maven
5,000+
npm
5,000+
NuGet
1,119
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,574
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
21 advisories
Filter by severity
Astro: Remote code execution through AVIF image optimization
Critical
GHSA-26w7-cxv4-gfx2
was published
for
astro
(npm)
Sep 8, 2026
surfio has an out-of-bounds read
Critical
CVE-2026-55211
was published
for
surfio
(pip)
Aug 18, 2026
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
Critical
CVE-2026-55209
was published
for
resdata
(pip)
Aug 18, 2026
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
Critical
CVE-2026-34987
was published
for
wasmtime
(Rust)
Apr 10, 2026
Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
Critical
CVE-2026-34971
was published
for
wasmtime
(Rust)
Apr 9, 2026
SiYuan has Arbitrary Document Reading within the Publishing Service
Critical
CVE-2026-33669
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 25, 2026
ExecuTorch out-of-bounds access vulnerability
Critical
CVE-2025-54950
was published
for
executorch
(Maven)
Aug 8, 2025
TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation
Critical
CVE-2023-25668
was published
for
tensorflow
(pip)
Mar 24, 2023
Deno improperly handles resizable ArrayBuffer
Critical
CVE-2023-28445
was published
for
Deno
(Rust)
Mar 23, 2023
wasmtime vulnerable to guest-controlled out-of-bounds read/write on x86_64
Critical
CVE-2023-26489
was published
for
cranelift-codegen
(Rust)
Mar 9, 2023
openssl-src contains Read Buffer Overflow in X.509 Name Constraint
Critical
CVE-2022-4203
was published
for
openssl-src
(Rust)
Feb 8, 2023
PaddlePaddle Out-of-bounds Read vulnerability
Critical
CVE-2022-46741
was published
for
paddlepaddle
(pip)
Dec 7, 2022
Out of bounds read in simple-slab
Critical
CVE-2020-35892
was published
for
simple-slab
(Rust)
Aug 25, 2021
Out of bounds access in lucet-runtime-internals
Critical
CVE-2020-35859
was published
for
lucet-runtime-internals
(Rust)
Aug 25, 2021
Out of bounds access in compact_arena
Critical
CVE-2019-16139
was published
for
compact_arena
(Rust)
Aug 25, 2021
Denial of Service in https-proxy-agent
Critical
CVE-2018-3739
was published
for
https-proxy-agent
(npm)
Jul 27, 2018
ProTip!
Advisories are also available from the
GraphQL API