GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,959 advisories
Filter by severity
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
High
GHSA-52vm-mxx8-f227
was published
for
phantom-audio
(pip)
Jul 9, 2026
Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer
High
CVE-2026-49361
was published
for
org.apache.fluss:fluss-common
(Maven)
Jun 1, 2026
Apache ActiveMQ Artemis Uncontrolled Resource Consumption (DoS)
High
CVE-2022-23913
was published
for
org.apache.activemq:artemis-core-client
(Maven)
Feb 6, 2022
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not...
High
Unreviewed
CVE-2026-9165
was published
Jul 6, 2026
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting...
High
Unreviewed
CVE-2025-6297
was published
Jul 1, 2025
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
High
CVE-2026-53530
was published
for
ratex-parser
(Rust)
Jul 7, 2026
BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre...
High
Unreviewed
CVE-2026-40140
was published
Jul 6, 2026
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7,...
High
Unreviewed
CVE-2026-45169
was published
Jun 12, 2026
SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
High
CVE-2026-46374
was published
for
sqlfluff
(pip)
May 19, 2026
Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
Some interface fails to impose...
High
Unreviewed
CVE-2026-24012
was published
Jul 6, 2026
An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of...
High
Unreviewed
CVE-2026-52192
was published
Jul 2, 2026
Scriban: Built-in operations bypass LoopLimit and delay cancellation, enabling Denial of Service
High
GHSA-c875-h985-hvrc
was published
for
Scriban.Signed
(NuGet)
Mar 24, 2026
An issue in Texas Instruments LP-CC2652RB SimpleLink CC13XX CC26XX SDK 7.41.00.17 allows...
High
Unreviewed
CVE-2025-44528
was published
Jun 23, 2025
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
High
CVE-2026-50196
was published
for
Steeltoe.Discovery.Eureka
(NuGet)
Jul 2, 2026
SimpleSAMLphp has Possible DoS via XPath Transform
High
CVE-2026-49289
was published
for
simplesamlphp/saml2
(Composer)
Jul 2, 2026
In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did...
High
Unreviewed
CVE-2026-9563
was published
Jul 2, 2026
Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache...
High
Unreviewed
CVE-2026-54428
was published
Jul 1, 2026
An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of...
High
Unreviewed
CVE-2026-52197
was published
Jul 1, 2026
Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache...
High
Unreviewed
CVE-2026-54399
was published
Jul 1, 2026
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication...
High
Unreviewed
CVE-2026-10143
was published
Jun 11, 2026
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS)...
High
Unreviewed
CVE-2026-5497
was published
Jun 11, 2026
The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect...
High
Unreviewed
CVE-2026-2891
was published
Jul 1, 2026
OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure
High
CVE-2026-35633
was published
for
openclaw
(npm)
Mar 26, 2026
Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
High
CVE-2026-47077
was published
for
hackney
(Erlang)
Jun 26, 2026
Duplicate Advisory: Hackney has an Allocation of Resources Without Limits or Throttling vulnerabilit
High
GHSA-76v6-f83q-pxvh
was published
for
hackney
(Erlang)
May 26, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API