GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
116 advisories
Filter by severity
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco...
High
Unreviewed
CVE-2026-20280
was published
Sep 2, 2026
qs: Denial of Service via Attacker Controlled isBuffer
Moderate
CVE-2026-82417
was published
for
qs
(npm)
Sep 2, 2026
Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose...
High
Unreviewed
CVE-2026-26446
was published
Aug 26, 2026
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10...
Moderate
Unreviewed
CVE-2026-65332
was published
Aug 18, 2026
This issue was addressed through improved state management. This issue is fixed in iOS 26.6.1 and...
Moderate
Unreviewed
CVE-2026-65351
was published
Aug 18, 2026
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10...
Moderate
Unreviewed
CVE-2026-65331
was published
Aug 18, 2026
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
Moderate
CVE-2026-56818
was published
for
io.netty:netty-codec-redis
(Maven)
Aug 7, 2026
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
Low
GHSA-qh5g-q395-cx4j
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
A vulnerability was detected in hunvreus devpush up to 0.4.6. Affected by this issue is the...
Low
Unreviewed
CVE-2026-16218
was published
Jul 19, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS...
High
Unreviewed
CVE-2026-20187
was published
Jul 15, 2026
A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series...
High
Unreviewed
CVE-2026-13753
was published
Jul 6, 2026
Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was...
High
Unreviewed
CVE-2026-12324
was published
Jun 16, 2026
Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
High
CVE-2026-44893
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jun 8, 2026
Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source...
Moderate
Unreviewed
CVE-2026-47316
was published
May 19, 2026
XiangShan (Open-source high-performance RISC-V processor) commit...
High
Unreviewed
CVE-2026-29643
was published
Apr 21, 2026
Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint
Moderate
CVE-2026-34388
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 30, 2026
2N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error...
Moderate
Unreviewed
CVE-2025-59787
was published
Mar 4, 2026
malcontent: Nested archive extraction failure can drop content from scan inputs
Moderate
CVE-2026-28407
was published
for
github.com/chainguard-dev/malcontent
(Go)
Feb 28, 2026
rPGP vulnerable to parser crash on crafted RSA secret key packets through CVE-2026-21895
High
GHSA-7587-4wv6-m68m
was published
for
pgp
(Rust)
Feb 13, 2026
An inconsistent user interface issue was addressed with improved state management. This issue is...
Moderate
Unreviewed
CVE-2026-20640
was published
Feb 12, 2026
Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP...
Moderate
Unreviewed
CVE-2026-1996
was published
Feb 10, 2026
Emmett-Core: Unhandled CookieError Exception Causing Denial of Service
High
CVE-2026-25577
was published
for
emmett-core
(pip)
Feb 10, 2026
chetans9 core-php-admin-panel through commit a94a780d6 contains an authentication bypass...
High
Unreviewed
CVE-2025-70758
was published
Feb 3, 2026
Decidim's private data exports can lead to data leaks
High
CVE-2025-65017
was published
for
decidim
(RubyGems)
Feb 3, 2026
CometBFT has inconsistencies between how commit signatures are verified and how block time is derived
High
GHSA-c32p-wcqj-j677
was published
for
github.com/cometbft/cometbft
(Go)
Jan 23, 2026
ProTip!
Advisories are also available from the
GraphQL API