GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,175
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
15 advisories
Filter by severity
Tornado has out-of-bounds memory access via C extension
Low
CVE-2026-49854
was published
for
tornado
(pip)
Jun 12, 2026
OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers
Moderate
CVE-2026-45684
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
diesel-async may expose uninitialized padding bytes for MySQL temporal columns
Low
GHSA-ff9q-rm55-q7qr
was published
for
diesel-async
(Rust)
May 7, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
CVE-2026-41898
was published
for
openssl
(Rust)
Apr 22, 2026
fido2-lib is vulnerable to DoS via cbor-extract heap buffer over-read in CBOR attestation parsing
High
GHSA-g3qj-j598-cxmq
was published
for
fido2-lib
(npm)
Mar 24, 2026
ImageMagick has a heap Buffer Over-read in its DJVU image format handler
Moderate
CVE-2026-27799
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: Heap Buffer Over-read in WaveletDenoise when processing small images
Moderate
CVE-2026-27798
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
Duplicate Advisory: `openssl` `X509VerifyParamRef::set_host` buffer over-read
Moderate
GHSA-gw89-822v-8v8g
was published
for
openssl
(Rust)
Jul 28, 2025
•
withdrawn
Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2025-21176
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jan 14, 2025
Databento Binary Encoding (DBN) has a heap buffer overflow using c_chars_to_str function
Moderate
GHSA-pfr9-2p92-qrhq
was published
for
dbn
(Rust)
Oct 9, 2024
StringIO buffer overread vulnerability
Critical
CVE-2024-27280
was published
for
stringio
(RubyGems)
Mar 25, 2024
`openssl` `X509VerifyParamRef::set_host` buffer over-read
Moderate
CVE-2023-53159
was published
for
openssl
(Rust)
Jun 21, 2023
Apache Tomcat Buffer Over-Read
High
CVE-2006-7197
was published
for
org.apache.tomcat:tomcat
(Maven)
May 1, 2022
Improper Input Validation and Buffer Over-read in mqtt-packet
High
CVE-2019-5432
was published
for
mqtt-packet
(npm)
May 14, 2019
ProTip!
Advisories are also available from the
GraphQL API