GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,959 advisories
Filter by severity
js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
High
CVE-2026-49293
was published
for
js-toml
(npm)
Jun 26, 2026
Hackney has unbounded buffer accumulation in WebSocket
High
CVE-2026-47073
was published
for
hackney
(Erlang)
Jun 26, 2026
Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
High
CVE-2026-47077
was published
for
hackney
(Erlang)
Jun 26, 2026
Hackney: `ssl:connect/2` post-handshake upgrade has no timeout
High
CVE-2026-47071
was published
for
hackney
(Erlang)
Jun 26, 2026
An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to...
High
Unreviewed
CVE-2026-30041
was published
Jun 26, 2026
An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers...
High
Unreviewed
CVE-2026-38637
was published
Jun 25, 2026
A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows...
High
Unreviewed
CVE-2026-38640
was published
Jun 25, 2026
Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service...
High
Unreviewed
CVE-2026-56248
was published
Jun 23, 2026
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2...
High
Unreviewed
CVE-2023-54365
was published
Jun 23, 2026
skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery
High
GHSA-74p7-6h78-gw8p
was published
for
skillctl
(Rust)
Jun 22, 2026
The public dashboard query endpoint does not limit request body size before processing, allowing...
High
Unreviewed
CVE-2026-42127
was published
Jun 22, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0...
High
Unreviewed
CVE-2026-9071
was published
Jun 22, 2026
SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
High
GHSA-xcqx-9jf5-w339
was published
for
mcp-searxng
(npm)
Jun 19, 2026
urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (...
High
Unreviewed
CVE-2026-9375
was published
Jun 19, 2026
Langflow: Unauthenticated DoS through multipart form boundary file upload
High
CVE-2026-55446
was published
for
langflow
(pip)
Jun 19, 2026
Ultimate Sitemap Parser (USP): Gzip Decompression Bomb Bypasses Sitemap Size Limit
High
GHSA-8823-qg2x-pv9f
was published
for
ultimate-sitemap-parser
(pip)
Jun 19, 2026
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
High
CVE-2026-54772
was published
for
CoreWCF.NetFramingBase
(NuGet)
Jun 19, 2026
undici WebSocket client vulnerable to denial of service via fragment count bypass
High
CVE-2026-12151
was published
for
undici
(npm)
Jun 19, 2026
PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service
High
GHSA-3prj-6hqw-cm82
was published
for
web-token/jwt-framework
(Composer)
Jun 18, 2026
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
High
CVE-2026-9675
was published
for
undici
(npm)
Jun 18, 2026
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
High
CVE-2026-56740
was published
for
org.jline:jline-remote-telnet
(Maven)
Jun 18, 2026
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
High
CVE-2026-56741
was published
for
org.jline:jline-remote-telnet
(Maven)
Jun 18, 2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager...
High
Unreviewed
CVE-2026-46866
was published
Jun 17, 2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server:...
High
Unreviewed
CVE-2026-46863
was published
Jun 17, 2026
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). ...
High
Unreviewed
CVE-2026-46862
was published
Jun 17, 2026
ProTip!
Advisories are also available from the
GraphQL API