GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
85 advisories
Filter by severity
Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it...
Moderate
Unreviewed
CVE-2026-14587
was published
Aug 5, 2026
FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket...
Critical
Unreviewed
CVE-2026-67292
was published
Aug 1, 2026
[This CNA information record relates to multiple CVEs; the
text explains which aspects...
Moderate
Unreviewed
CVE-2026-62423
was published
Jul 28, 2026
[This CNA information record relates to multiple CVEs; the
text explains which aspects...
Moderate
Unreviewed
CVE-2026-62424
was published
Jul 28, 2026
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN...
Moderate
Unreviewed
CVE-2026-26081
was published
Jul 20, 2026
Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2...
Moderate
Unreviewed
CVE-2026-60060
was published
Jul 17, 2026
websocket-driver: Message corruption via abuse of protocol length headers
Critical
CVE-2026-54466
was published
for
websocket-driver
(npm)
Jul 15, 2026
Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or...
Moderate
Unreviewed
CVE-2026-6432
was published
Jun 25, 2026
zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet
Moderate
CVE-2026-48487
was published
for
zeroconf
(pip)
Jun 22, 2026
FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly...
Moderate
Unreviewed
CVE-2026-48685
was published
May 26, 2026
An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size...
Critical
Unreviewed
CVE-2026-9054
was published
May 22, 2026
OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size
Moderate
CVE-2026-45681
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
In the Linux kernel, the following vulnerability has been resolved:
dlm: validate length in...
Critical
Unreviewed
CVE-2026-43125
was published
May 6, 2026
Django has an Improper Handling of Length Parameter Inconsistency
Moderate
CVE-2026-5766
was published
for
Django
(pip)
May 5, 2026
A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of...
High
Unreviewed
CVE-2026-33846
was published
May 4, 2026
An improper handling of the length parameter inconsistency vulnerability has been identified in...
High
Unreviewed
CVE-2026-3868
was published
Apr 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: fix oversized...
High
Unreviewed
CVE-2026-31635
was published
Apr 24, 2026
When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a...
Moderate
Unreviewed
CVE-2026-5265
was published
Apr 24, 2026
A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 ...
High
Unreviewed
CVE-2026-5367
was published
Apr 24, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
CVE-2026-41898
was published
for
openssl
(Rust)
Apr 22, 2026
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort...
High
Unreviewed
CVE-2026-41035
was published
Apr 16, 2026
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the...
Moderate
Unreviewed
CVE-2026-33555
was published
Apr 13, 2026
Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may...
Moderate
Unreviewed
CVE-2026-40199
was published
Apr 11, 2026
Rack has Content-Length mismatch in Rack::Files error responses
Moderate
CVE-2026-34831
was published
for
rack
(RubyGems)
Apr 2, 2026
python-ecdsa: Denial of Service via improper DER length validation in crafted private keys
Moderate
CVE-2026-33936
was published
for
ecdsa
(pip)
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API