GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,638
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
85 advisories
Filter by severity
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
Critical
CVE-2026-55209
was published
for
resdata
(pip)
Aug 18, 2026
Open Babel has out-of-bounds write in CSR PadString (title field)
High
CVE-2022-41793
was published
for
openbabel
(pip)
Jul 1, 2026
pdfkit: Path traversal in from_string
High
CVE-2025-26240
was published
for
pdfkit
(pip)
Jun 17, 2026
Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
Critical
CVE-2026-54257
was published
for
electron
(npm)
Jun 15, 2026
libcrux: Potential Panic on Overlong Ciphertext Buffer
High
GHSA-hc3c-63hc-2r9f
was published
for
libcrux-chacha20poly1305
(Rust)
May 19, 2026
Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
Moderate
CVE-2026-27820
was published
for
zlib
(RubyGems)
Apr 16, 2026
OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()
Moderate
CVE-2025-64182
was published
for
OpenEXR
(pip)
Apr 6, 2026
pyOpenSSL DTLS cookie callback buffer overflow
High
CVE-2026-27459
was published
for
pyopenssl
(pip)
Mar 16, 2026
fast-xml-parser has stack overflow in XMLBuilder with preserveOrder
Low
CVE-2026-27942
was published
for
fast-xml-parser
(npm)
Feb 26, 2026
Quick-Media Batik Codec FIX Package has Buffer Overflow Vulnerability in PNG Codec
Moderate
CVE-2026-24807
was published
for
com.github.liuyueyi.media:batik-codec-fix
(Maven)
Jan 27, 2026
Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
Moderate
CVE-2025-68383
was published
for
github.com/elastic/beats
(Go)
Dec 19, 2025
binary_vec_io access memory out-of-bounds in binary_read_to_ref and binary_write_from_ref
High
GHSA-wwxp-hxh6-8gf8
was published
for
binary_vec_io
(Rust)
Oct 22, 2025
NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
Critical
CVE-2025-54469
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
SPDK is vulnerable to buffer overflow in the NVMe-oF target component
Moderate
CVE-2025-57275
was published
for
spdk
(pip)
Oct 1, 2025
bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function
High
CVE-2025-3194
was published
for
bigint-buffer
(npm)
Apr 4, 2025
Django vulnerable to denial-of-service attack via the urlize() and urlizetrunc() template filters
Moderate
CVE-2024-45230
was published
for
Django
(pip)
Oct 8, 2024
zerovec-derive incorrectly uses `#[repr(packed)]`
Moderate
GHSA-74r5-g7vc-j2v2
was published
for
zerovec-derive
(Rust)
Jul 8, 2024
zerovec incorrectly uses `#[repr(packed)]`
Moderate
GHSA-xrv3-jmcp-374j
was published
for
zerovec
(Rust)
Jul 8, 2024
rockhopper Buffer Overflow vulnerability
Moderate
CVE-2022-4969
was published
for
rockhopper
(pip)
May 28, 2024
Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459
Low
GHSA-r95h-9x8f-r3f7
was published
for
nokogiri
(RubyGems)
May 13, 2024
pywasm3 contains a global buffer overflow which leads to segmentation fault
Critical
CVE-2024-34252
was published
for
pywasm3
(pip)
May 6, 2024
Buffer Overflow vulnerability in osrg gobgp
High
CVE-2023-46565
was published
for
github.com/osrg/gobgp/v3
(Go)
Apr 29, 2024
transpose: Buffer overflow due to integer overflow
Moderate
CVE-2023-53156
was published
for
transpose
(Rust)
Apr 5, 2024
ProTip!
Advisories are also available from the
GraphQL API