GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
585 advisories
Filter by severity
A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() function may crash when...
Moderate
Unreviewed
CVE-2025-32051
was published
Apr 3, 2025
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
Moderate
CVE-2026-54775
was published
for
CoreWCF.Kafka
(NuGet)
Jun 19, 2026
OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads
High
CVE-2026-45678
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
Clerk has an authorization bypass when combining organization, billing, or reverification checks
High
CVE-2026-42349
was published
for
@clerk/astro
(npm)
Apr 30, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)
Moderate
CVE-2026-44324
was published
for
github.com/free5gc/udr
(Go)
May 8, 2026
free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference
High
CVE-2026-44322
was published
for
github.com/free5gc/nef
(Go)
May 8, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference
Moderate
CVE-2026-44317
was published
for
github.com/free5gc/pcf
(Go)
May 8, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference
High
CVE-2026-44316
was published
for
github.com/free5gc/pcf
(Go)
May 8, 2026
In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates...
Critical
Unreviewed
CVE-2025-48581
was published
Sep 4, 2025
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service...
High
Unreviewed
CVE-2026-5343
was published
May 29, 2026
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon...
Moderate
Unreviewed
CVE-2019-6856
was published
May 24, 2022
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon...
Moderate
Unreviewed
CVE-2019-6857
was published
May 24, 2022
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could...
High
Unreviewed
CVE-2019-6819
was published
May 24, 2022
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon...
Moderate
Unreviewed
CVE-2018-7794
was published
May 24, 2022
An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider...
High
Unreviewed
CVE-2018-7789
was published
May 13, 2022
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web...
Moderate
Unreviewed
CVE-2020-7549
was published
May 24, 2022
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Quantum...
Moderate
Unreviewed
CVE-2020-7477
was published
May 24, 2022
Mattermost doesn't validate the response body of proxied images
Moderate
CVE-2026-4054
was published
for
github.com/mattermost/mattermost-server
(Go)
May 15, 2026
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation...
High
Unreviewed
CVE-2025-13392
was published
May 27, 2026
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View...
Low
Unreviewed
CVE-2026-8491
was published
May 20, 2026
Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source...
Moderate
Unreviewed
CVE-2026-47315
was published
May 19, 2026
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from...
Low
Unreviewed
CVE-2026-4643
was published
May 18, 2026
net-imap vulnerable to STARTTLS stripping via invalid response timing
High
CVE-2026-42246
was published
for
net-imap
(RubyGems)
May 4, 2026
ELECOM wireless LAN access point devices do not check if language parameter has an appropriate...
Moderate
Unreviewed
CVE-2026-42950
was published
May 13, 2026
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts
High
CVE-2026-40069
was published
for
bsv-sdk
(RubyGems)
Apr 9, 2026
ProTip!
Advisories are also available from the
GraphQL API