Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

85 advisories

Loading
[This CNA information record relates to multiple CVEs; the text explains which aspects... Moderate Unreviewed
CVE-2026-62423 was published Jul 28, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects... Moderate Unreviewed
CVE-2026-62424 was published Jul 28, 2026
websocket-driver: Message corruption via abuse of protocol length headers Critical
CVE-2026-54466 was published for websocket-driver (npm) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size Moderate
CVE-2026-45681 was published for go.opentelemetry.io/obi (Go) May 18, 2026
MrAlias Credited to MrAlias, rafaelroquetto, and mmat11 rafaelroquetto rafaelroquetto
mmat11 mmat11
Django has an Improper Handling of Length Parameter Inconsistency Moderate
CVE-2026-5766 was published for Django (pip) May 5, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer High
CVE-2026-41898 was published for openssl (Rust) Apr 22, 2026
Rack has Content-Length mismatch in Rack::Files error responses Moderate
CVE-2026-34831 was published for rack (RubyGems) Apr 2, 2026
Oblivionsage Credited to Oblivionsage, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
python-ecdsa: Denial of Service via improper DER length validation in crafted private keys Moderate
CVE-2026-33936 was published for ecdsa (pip) Mar 27, 2026
0xmrma Credited to 0xmrma
ProTip! Advisories are also available from the GraphQL API