GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
443 advisories
Filter by severity
In the Linux kernel, the following vulnerability has been resolved:
arm64: Reserve an extra page...
Moderate
Unreviewed
CVE-2026-53288
was published
Jun 26, 2026
Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)
Moderate
GHSA-6q7j-xr26-3h2c
was published
for
Scriban
(NuGet)
Jun 26, 2026
ImageMagick Vulnerable to Stack Overflow in its MVG Decoder
Moderate
CVE-2026-48734
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement
Moderate
CVE-2026-48513
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
Moderate
CVE-2026-48512
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
High
CVE-2026-48506
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
High
CVE-2026-48502
was published
for
MessagePack
(NuGet)
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_ct: bail out...
High
Unreviewed
CVE-2026-53267
was published
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
accel/ivpu: Fix signed...
High
Unreviewed
CVE-2026-53202
was published
Jun 25, 2026
MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS...
High
Unreviewed
CVE-2025-71382
was published
Jun 23, 2026
SurrealDB: Denial of Service via deep operator chains
Moderate
GHSA-jv2j-mqmw-xvv5
was published
for
surrealdb
(Rust)
Jun 19, 2026
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
High
CVE-2026-54297
was published
for
faraday
(RubyGems)
Jun 19, 2026
protobufjs: Denial of service through unbounded Any expansion during JSON conversion
High
CVE-2026-48712
was published
for
protobufjs
(npm)
Jun 15, 2026
protobufjs : Schema-derived names can shadow runtime-significant properties
Moderate
CVE-2026-54269
was published
for
protobufjs
(npm)
Jun 15, 2026
Stack overflow vulnerability due to uncontrolled recursion in Avast Antivirus when scanning a...
Moderate
Unreviewed
CVE-2025-7010
was published
Jun 13, 2026
Uncontrolled recursion vulnerability in Avast Antivirus when scanning a malformed Windows PE file...
Moderate
Unreviewed
CVE-2025-7005
was published
Jun 13, 2026
A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash...
High
Unreviewed
CVE-2026-9740
was published
Jun 10, 2026
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses.
The add method...
High
Unreviewed
CVE-2026-49941
was published
Jun 4, 2026
Strawberry GraphQL has a Circular Fragment Reference DOS
Moderate
CVE-2026-47706
was published
for
strawberry-graphql
(pip)
Jun 4, 2026
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized...
Moderate
Unreviewed
CVE-2026-47306
was published
Jun 4, 2026
Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source...
Moderate
Unreviewed
CVE-2026-47320
was published
Jun 4, 2026
Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container...
High
Unreviewed
CVE-2026-8936
was published
Jun 3, 2026
Spring Cloud Function Context has Uncontrolled Recursion
Moderate
CVE-2026-40989
was published
for
org.springframework.cloud:spring-cloud-function-context
(Maven)
Jun 1, 2026
zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service
Moderate
CVE-2026-47180
was published
for
zeroconf
(pip)
May 29, 2026
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vcn4: Avoid...
Moderate
Unreviewed
CVE-2026-46217
was published
May 28, 2026
ProTip!
Advisories are also available from the
GraphQL API