GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
364 advisories
Filter by severity
In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so...
High
Unreviewed
CVE-2026-71891
was published
Oct 3, 2026
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5...
High
Unreviewed
CVE-2026-104435
was published
Oct 2, 2026
Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature...
High
Unreviewed
CVE-2026-104437
was published
Oct 2, 2026
An improper verification of cryptographic signature vulnerability exists in protocol gateways...
High
Unreviewed
CVE-2026-86326
was published
Oct 2, 2026
Improper verification of cryptographic signature in the attribute certificate path validator ...
High
Unreviewed
CVE-2026-63571
was published
Oct 2, 2026
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where...
High
Unreviewed
CVE-2026-47554
was published
Sep 30, 2026
The device's update mechanism includes conditions that allow unauthorized software packages to be...
High
Unreviewed
CVE-2026-91191
was published
Sep 30, 2026
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
High
CVE-2026-102266
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT accepts public JWK containers as HMAC secrets
High
CVE-2026-102273
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
High
CVE-2026-102271
was published
for
pyjwt
(pip)
Sep 29, 2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms...
High
Unreviewed
CVE-2026-100293
was published
Sep 29, 2026
MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears...
High
Unreviewed
CVE-2026-97731
was published
Sep 25, 2026
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
High
CVE-2026-57178
was published
for
social-auth-core
(pip)
Sep 24, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to...
High
Unreviewed
CVE-2026-18152
was published
Sep 23, 2026
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy)...
High
Unreviewed
CVE-2026-75939
was published
Sep 21, 2026
A flaw was found in the signature verification logic of noobaa-core, the core component of the...
High
Unreviewed
CVE-2026-94368
was published
Sep 21, 2026
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the...
High
Unreviewed
CVE-2026-93657
was published
Sep 18, 2026
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
High
CVE-2026-86038
was published
for
@libp2p/gossipsub
(npm)
Sep 17, 2026
Nuclei versions before 3.11.1 cache template signature verification based only on file...
High
Unreviewed
CVE-2026-92718
was published
Sep 16, 2026
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older...
High
Unreviewed
CVE-2026-42784
was published
Sep 16, 2026
The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors,...
High
Unreviewed
CVE-2026-86585
was published
Sep 16, 2026
The VeloCloud Edge software update workflow may accept update bundles without properly validating...
High
Unreviewed
CVE-2026-86109
was published
Sep 16, 2026
An attacker may achieve arbitrary code execution on a target system by uploading a malicious...
High
Unreviewed
CVE-2026-80469
was published
Sep 11, 2026
A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML...
High
Unreviewed
CVE-2026-73784
was published
Sep 11, 2026
ProTip!
Advisories are also available from the
GraphQL API