GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
585 advisories
Filter by severity
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)
Moderate
CVE-2026-44324
was published
for
github.com/free5gc/udr
(Go)
May 8, 2026
free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference
High
CVE-2026-44322
was published
for
github.com/free5gc/nef
(Go)
May 8, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference
Moderate
CVE-2026-44317
was published
for
github.com/free5gc/pcf
(Go)
May 8, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference
High
CVE-2026-44316
was published
for
github.com/free5gc/pcf
(Go)
May 8, 2026
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was...
Critical
Unreviewed
CVE-2026-8091
was published
May 7, 2026
net-imap vulnerable to STARTTLS stripping via invalid response timing
High
CVE-2026-42246
was published
for
net-imap
(RubyGems)
May 4, 2026
Clerk has an authorization bypass when combining organization, billing, or reverification checks
High
CVE-2026-42349
was published
for
@clerk/astro
(npm)
Apr 30, 2026
Admidio Missing Minimum Administrator Check in Role Membership Removal
Moderate
CVE-2026-41662
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
An unauthenticated remote attacker is able to exhaust all available TCP connections in the...
High
Unreviewed
CVE-2026-35225
was published
Apr 23, 2026
nimiq-blockchain: Peer-triggerable panic during history sync
Moderate
CVE-2026-34066
was published
for
nimiq-blockchain
(Rust)
Apr 22, 2026
Duplicate Advisory: uutils coreutils has an Improper Check for Unusual or Exceptional Conditions
Moderate
GHSA-7259-cwhx-3xx3
was published
for
coreutils
(Rust)
Apr 22, 2026
•
withdrawn
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation
Moderate
CVE-2026-40343
was published
for
github.com/free5gc/udr
(Go)
Apr 21, 2026
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in...
High
Unreviewed
CVE-2026-6772
was published
Apr 21, 2026
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in...
High
Unreviewed
CVE-2026-6766
was published
Apr 21, 2026
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or...
Moderate
Unreviewed
CVE-2025-43883
was published
Apr 16, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors
Moderate
CVE-2026-40249
was published
for
github.com/free5gc/udr
(Go)
Apr 14, 2026
Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows...
Moderate
Unreviewed
CVE-2026-21007
was published
Apr 13, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding...
Moderate
Unreviewed
CVE-2026-33774
was published
Apr 10, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control...
Moderate
Unreviewed
CVE-2026-33787
was published
Apr 10, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control...
Moderate
Unreviewed
CVE-2026-33786
was published
Apr 10, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding...
High
Unreviewed
CVE-2026-33781
was published
Apr 10, 2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd)...
High
Unreviewed
CVE-2026-33790
was published
Apr 10, 2026
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts
High
CVE-2026-40069
was published
for
bsv-sdk
(RubyGems)
Apr 9, 2026
Issue summary: Applications using RSASVE key encapsulation to establish
a secret encryption key...
High
Unreviewed
CVE-2026-31790
was published
Apr 8, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails
Moderate
CVE-2026-39395
was published
for
github.com/sigstore/cosign
(Go)
Apr 8, 2026
ProTip!
Advisories are also available from the
GraphQL API