GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
443 advisories
Filter by severity
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: configfs:...
High
Unreviewed
CVE-2026-46149
was published
May 28, 2026
Symfony hardened the parser when handling untrusted input
Low
CVE-2026-45133
was published
for
symfony/symfony
(Composer)
May 27, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled...
Moderate
Unreviewed
CVE-2026-6936
was published
May 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
powerpc/eeh: fix recursive...
Moderate
Unreviewed
CVE-2026-45904
was published
May 27, 2026
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack...
Moderate
Unreviewed
CVE-2026-7453
was published
May 26, 2026
SQLFluff: Recursive Stack Overflow in Parser
High
CVE-2026-46373
was published
for
sqlfluff
(pip)
May 19, 2026
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
Moderate
CVE-2026-45740
was published
for
protobufjs
(npm)
May 19, 2026
Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Excessive Allocation....
Moderate
Unreviewed
CVE-2026-47317
was published
May 19, 2026
Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized...
Moderate
Unreviewed
CVE-2026-47309
was published
May 19, 2026
ImageMagick: Stack overflow in fx operation
Moderate
CVE-2026-46557
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
ImageMagick: Policy Bypass in MNG coder could
Moderate
CVE-2026-45664
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when...
Moderate
Unreviewed
CVE-2026-6811
was published
May 15, 2026
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect...
High
Unreviewed
CVE-2026-6479
was published
May 14, 2026
Apache Commons Configuration: StackOverflowError for YAML input with cycles
Moderate
CVE-2026-45205
was published
for
org.apache.commons:commons-configuration2
(Maven)
May 14, 2026
go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion
Moderate
CVE-2026-44740
was published
for
github.com/go-git/go-billy/v5
(Go)
May 13, 2026
protobuf.js: Denial of service through unbounded protobuf recursion
High
CVE-2026-44289
was published
for
protobufjs
(npm)
May 12, 2026
eml_parser has recursion DoS via nested message/rfc822 attachments
Moderate
CVE-2026-44844
was published
for
eml_parser
(pip)
May 8, 2026
go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth
Moderate
CVE-2026-42328
was published
for
github.com/ipld/go-ipld-prime
(Go)
May 7, 2026
ldap3_proto has LDAP Filter stack exhaustion
High
GHSA-qcxq-75wr-5cm8
was published
for
ldap3_proto
(Rust)
May 6, 2026
scim_proto and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustion
High
CVE-2026-46689
was published
for
kanidm_proto
(Rust)
May 6, 2026
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix signededness bug...
Critical
Unreviewed
CVE-2026-43185
was published
May 6, 2026
In the Linux kernel, the following vulnerability has been resolved:
l2tp: Drop large packets...
Moderate
Unreviewed
CVE-2026-43080
was published
May 6, 2026
webonyx/graphql-php has unbounded recursion in parser that causes stack overflow on crafted nested input
High
GHSA-r7cg-qjjm-xhqq
was published
for
webonyx/graphql-php
(Composer)
May 5, 2026
An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the...
High
Unreviewed
CVE-2026-44028
was published
May 5, 2026
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
Moderate
CVE-2026-42039
was published
for
axios
(npm)
May 5, 2026
ProTip!
Advisories are also available from the
GraphQL API