GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
585 advisories
Filter by severity
OpenClaw: Security Scan Failure Does Not Block Plugin Installation (Fail-Open)
Low
CVE-2026-41377
was published
for
openclaw
(npm)
Apr 2, 2026
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
High
CVE-2026-33939
was published
for
handlebars
(npm)
Mar 27, 2026
Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which...
Low
Unreviewed
CVE-2026-3109
was published
Mar 26, 2026
Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds
Moderate
CVE-2026-20719
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 25, 2026
@grackle-ai/server JSON.parse lacks try-catch logic in its gRPC Service AdapterConfig Handling
Low
GHSA-8g29-8xwr-qmhr
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability...
High
Unreviewed
CVE-2026-4697
was published
Mar 24, 2026
Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability affects...
High
Unreviewed
CVE-2026-4699
was published
Mar 24, 2026
Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability...
High
Unreviewed
CVE-2026-4695
was published
Mar 24, 2026
Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability...
High
Unreviewed
CVE-2026-4694
was published
Mar 24, 2026
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects...
High
Unreviewed
CVE-2026-4707
was published
Mar 24, 2026
Incorrect boundary conditions in the Audio/Video component. This vulnerability affects Firefox <...
High
Unreviewed
CVE-2026-4714
was published
Mar 24, 2026
Incorrect boundary conditions in the Graphics: Text component. This vulnerability affects Firefox...
High
Unreviewed
CVE-2026-4719
was published
Mar 24, 2026
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability affects...
High
Unreviewed
CVE-2026-4709
was published
Mar 24, 2026
Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 149...
High
Unreviewed
CVE-2026-4713
was published
Mar 24, 2026
Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 149...
High
Unreviewed
CVE-2026-4708
was published
Mar 24, 2026
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects...
High
Unreviewed
CVE-2026-4706
was published
Mar 24, 2026
Sandbox escape due to incorrect boundary conditions in the Telemetry component. This...
High
Unreviewed
CVE-2026-4687
was published
Mar 24, 2026
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability affects...
High
Unreviewed
CVE-2026-4693
was published
Mar 24, 2026
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects...
High
Unreviewed
CVE-2026-4685
was published
Mar 24, 2026
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects...
High
Unreviewed
CVE-2026-4686
was published
Mar 24, 2026
socket.io allows an unbounded number of binary attachments
High
CVE-2026-33151
was published
for
socket.io-parser
(npm)
Mar 18, 2026
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows...
Moderate
Unreviewed
CVE-2026-0230
was published
Mar 11, 2026
Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may...
High
Unreviewed
CVE-2026-30900
was published
Mar 11, 2026
In dhd_tcpdata_info_get of dhd_ip.c, there is a possible Denial of Service due to a precondition...
High
Unreviewed
CVE-2026-0109
was published
Mar 10, 2026
RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface
Critical
CVE-2026-30960
was published
for
rssn
(Rust)
Mar 10, 2026
ProTip!
Advisories are also available from the
GraphQL API