GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
85 advisories
Filter by severity
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
Critical
CVE-2026-55209
was published
for
resdata
(pip)
Aug 18, 2026
Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
Critical
CVE-2026-54257
was published
for
electron
(npm)
Jun 15, 2026
Open Babel has out-of-bounds write in CSR PadString (title field)
High
CVE-2022-41793
was published
for
openbabel
(pip)
Jul 1, 2026
Duplicate Advisory: Open Babel has out-of-bounds write in CSR PadString (title field)
Critical
GHSA-jmf7-79p7-qchq
was published
for
openbabel
(pip)
Jul 21, 2023
•
withdrawn
pdfkit: Path traversal in from_string
High
CVE-2025-26240
was published
for
pdfkit
(pip)
Jun 17, 2026
pywasm3 contains a global buffer overflow which leads to segmentation fault
Critical
CVE-2024-34252
was published
for
pywasm3
(pip)
May 6, 2024
Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
Moderate
CVE-2026-27820
was published
for
zlib
(RubyGems)
Apr 16, 2026
libcrux: Potential Panic on Overlong Ciphertext Buffer
High
GHSA-hc3c-63hc-2r9f
was published
for
libcrux-chacha20poly1305
(Rust)
May 19, 2026
OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()
Moderate
CVE-2025-64182
was published
for
OpenEXR
(pip)
Apr 6, 2026
Vyper's `_abi_decode` vulnerable to Memory Overflow
Low
CVE-2024-26149
was published
for
vyper
(pip)
Feb 26, 2024
pyOpenSSL DTLS cookie callback buffer overflow
High
CVE-2026-27459
was published
for
pyopenssl
(pip)
Mar 16, 2026
Potential buffer overflow in CBOR2 decoder
High
CVE-2024-26134
was published
for
cbor2
(pip)
Feb 21, 2024
fast-xml-parser has stack overflow in XMLBuilder with preserveOrder
Low
CVE-2026-27942
was published
for
fast-xml-parser
(npm)
Feb 26, 2026
Quick-Media Batik Codec FIX Package has Buffer Overflow Vulnerability in PNG Codec
Moderate
CVE-2026-24807
was published
for
com.github.liuyueyi.media:batik-codec-fix
(Maven)
Jan 27, 2026
odoh-rs's Invalid Slice Split Results in Server Panic
Moderate
CVE-2023-3766
was published
for
odoh-rs
(Rust)
Aug 3, 2023
Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
Moderate
CVE-2025-68383
was published
for
github.com/elastic/beats
(Go)
Dec 19, 2025
X.509 Email Address 4-byte Buffer Overflow
Critical
CVE-2022-3602
was published
for
openssl-src
(Rust)
Nov 1, 2022
StringIO buffer overread vulnerability
Critical
CVE-2024-27280
was published
for
stringio
(RubyGems)
Mar 25, 2024
NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
Critical
CVE-2025-54469
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
binary_vec_io access memory out-of-bounds in binary_read_to_ref and binary_write_from_ref
High
GHSA-wwxp-hxh6-8gf8
was published
for
binary_vec_io
(Rust)
Oct 22, 2025
SPDK is vulnerable to buffer overflow in the NVMe-oF target component
Moderate
CVE-2025-57275
was published
for
spdk
(pip)
Oct 1, 2025
Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459
Low
GHSA-r95h-9x8f-r3f7
was published
for
nokogiri
(RubyGems)
May 13, 2024
transpose: Buffer overflow due to integer overflow
Moderate
CVE-2023-53156
was published
for
transpose
(Rust)
Apr 5, 2024
bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function
High
CVE-2025-3194
was published
for
bigint-buffer
(npm)
Apr 4, 2025
hutool Buffer Overflow vulnerability
High
CVE-2023-42278
was published
for
cn.hutool:hutool-core
(Maven)
Sep 9, 2023
ProTip!
Advisories are also available from the
GraphQL API