GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
104
GitHub Actions
54
Go
4,450
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,134
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
3,852 advisories
Filter by severity
The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per...
High
Unreviewed
CVE-2026-58182
was published
Jul 29, 2026
Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses,...
High
Unreviewed
CVE-2026-65324
was published
Jul 29, 2026
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing...
High
Unreviewed
CVE-2026-58151
was published
Jul 29, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0...
High
Unreviewed
CVE-2026-14981
was published
Jul 28, 2026
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This...
High
Unreviewed
CVE-2026-66299
was published
Jul 28, 2026
Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph...
High
Unreviewed
CVE-2026-66920
was published
Jul 28, 2026
Addressing certain issues, in particular related to operations which may
take excessively long...
High
Unreviewed
CVE-2026-42493
was published
Jul 28, 2026
An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via...
High
Unreviewed
CVE-2025-63913
was published
Jul 28, 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS...
Moderate
Unreviewed
CVE-2026-64724
was published
Jul 27, 2026
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7...
Moderate
Unreviewed
CVE-2026-43768
was published
Jul 27, 2026
A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in...
Moderate
Unreviewed
CVE-2026-43806
was published
Jul 27, 2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.6,...
Moderate
Unreviewed
CVE-2026-43804
was published
Jul 27, 2026
A logic issue existed resulting in memory corruption. This was addressed with improved state...
Moderate
Unreviewed
CVE-2026-28932
was published
Jul 27, 2026
A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function...
Moderate
Unreviewed
CVE-2026-17501
was published
Jul 27, 2026
libp2p: yamux connection DoS via oversized data frame
High
GHSA-hmj8-5xmh-5573
was published
for
libp2p
(pip)
Jul 24, 2026
Shescape: Quadratic-time denial of service in the flag-protection
High
GHSA-gm3r-q2wp-hw87
was published
for
shescape
(npm)
Jul 24, 2026
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
High
CVE-2026-14257
was published
for
brace-expansion
(npm)
Jul 24, 2026
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
High
GHSA-g5vv-q72c-7j78
was published
for
@anephenix/hub
(npm)
Jul 24, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Critical
GHSA-68r5-9hpg-7qw9
was published
for
org.openidentityplatform.opendj:opendj-dsml-servlet
(Maven)
Jul 24, 2026
react-server-dom: Denial of Service in Server Functions
High
CVE-2026-44907
was published
for
react-server-dom-parcel
(npm)
Jul 24, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Moderate
CVE-2026-55497
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
High
GHSA-v74w-7mr3-4qg3
was published
for
io.netty:netty-codec-xml
(Maven)
Jul 24, 2026
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Moderate
GHSA-r292-9mhp-454m
was published
for
tar
(npm)
Jul 24, 2026
It is possible to bypass the maximum number of normalized policy alternatives that was introduced...
High
Unreviewed
CVE-2026-66143
was published
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API