GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
110 advisories
Filter by severity
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
High
CVE-2026-55484
was published
for
github.com/guno1928/alos-http
(Go)
Aug 28, 2026
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Moderate
CVE-2026-73430
was published
for
russh
(Rust)
Jul 24, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Moderate
CVE-2026-73429
was published
for
russh
(Rust)
Jul 24, 2026
Socket.IO: Zero-attachment Memory Exhaustion
High
CVE-2026-69185
was published
for
socket.io-parser
(npm)
Aug 3, 2026
protobufjs : Schema-derived names can shadow runtime-significant properties
Moderate
CVE-2026-54269
was published
for
protobufjs
(npm)
Jun 15, 2026
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
Moderate
CVE-2026-35366
was published
for
uu_printenv
(Rust)
Jul 6, 2026
Duplicate Advisory: uutils coreutils has an Improper Check for Unusual or Exceptional Conditions
Moderate
GHSA-7259-cwhx-3xx3
was published
for
coreutils
(Rust)
Apr 22, 2026
•
withdrawn
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
Moderate
CVE-2026-35369
was published
for
uu_kill
(Rust)
Jul 6, 2026
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers
Moderate
GHSA-c8w6-x74f-vmg3
was published
for
zebra-rpc
(Rust)
Jul 2, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
Moderate
GHSA-4v76-cw68-4vc9
was published
for
surrealdb
(Rust)
Jul 1, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
High
GHSA-wjjj-24cx-f28g
was published
for
surrealdb
(Rust)
Jul 1, 2026
Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing
Moderate
CVE-2026-4915
was published
for
github.com/mattermost/mattermost-server
(Go)
May 26, 2026
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
Moderate
CVE-2026-54775
was published
for
CoreWCF.Kafka
(NuGet)
Jun 19, 2026
OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads
High
CVE-2026-45678
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
Clerk has an authorization bypass when combining organization, billing, or reverification checks
High
CVE-2026-42349
was published
for
@clerk/astro
(npm)
Apr 30, 2026
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)
Moderate
CVE-2026-44324
was published
for
github.com/free5gc/udr
(Go)
May 8, 2026
free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference
High
CVE-2026-44322
was published
for
github.com/free5gc/nef
(Go)
May 8, 2026
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference
Moderate
CVE-2026-44317
was published
for
github.com/free5gc/pcf
(Go)
May 8, 2026
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference
High
CVE-2026-44316
was published
for
github.com/free5gc/pcf
(Go)
May 8, 2026
Mattermost doesn't validate the response body of proxied images
Moderate
CVE-2026-4054
was published
for
github.com/mattermost/mattermost-server
(Go)
May 15, 2026
net-imap vulnerable to STARTTLS stripping via invalid response timing
High
CVE-2026-42246
was published
for
net-imap
(RubyGems)
May 4, 2026
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts
High
CVE-2026-40069
was published
for
bsv-sdk
(RubyGems)
Apr 9, 2026
PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF
High
CVE-2024-4367
was published
for
pdfjs-dist
(npm)
May 7, 2024
Admidio Missing Minimum Administrator Check in Role Membership Removal
Moderate
CVE-2026-41662
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
High
CVE-2026-25639
was published
for
axios
(npm)
Feb 9, 2026
ProTip!
Advisories are also available from the
GraphQL API