GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,016
Maven
5,000+
npm
4,737
NuGet
814
pip
4,347
Pub
12
RubyGems
987
Rust
1,140
Swift
50
Unreviewed advisories
All unreviewed
5,000+
57 advisories
Filter by severity
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric...
Moderate
Unreviewed
CVE-2025-48022
was published
Feb 13, 2026
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized...
High
Unreviewed
CVE-2025-14847
was published
Dec 19, 2025
rPGP Panics on Malformed Untrusted Input
High
CVE-2024-53856
was published
for
pgp
(Rust)
Dec 5, 2024
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the...
High
Unreviewed
CVE-2021-43666
was published
Mar 25, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP...
Moderate
Unreviewed
CVE-2021-27861
was published
Sep 28, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP...
Moderate
Unreviewed
CVE-2021-27862
was published
Sep 28, 2022
Django vulnerable to denial-of-service attack
Moderate
CVE-2024-41991
was published
for
Django
(pip)
Aug 7, 2024
Django vulnerable to a denial-of-service attack
Moderate
CVE-2024-41990
was published
for
Django
(pip)
Aug 7, 2024
Django vulnerable to Denial of Service
High
CVE-2024-39614
was published
for
Django
(pip)
Jul 10, 2024
Django vulnerable to Denial of Service
High
CVE-2024-38875
was published
for
Django
(pip)
Jul 10, 2024
Elliptic's ECDSA missing check for whether leading bit of r and s is zero
Low
CVE-2024-42460
was published
for
elliptic
(npm)
Aug 2, 2024
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric...
Moderate
Unreviewed
CVE-2025-8531
was published
Sep 19, 2025
In multiple locations, there is a possible way to persistently DoS the device due to a missing...
Moderate
Unreviewed
CVE-2025-26432
was published
Sep 5, 2025
Improper Handling of Length Parameter Inconsistency vulnerability in web server function on...
Moderate
Unreviewed
CVE-2025-5514
was published
Aug 25, 2025
Vulnerability of inadequate packet length check in the BLE module.
Impact: Successful...
Moderate
Unreviewed
CVE-2025-54646
was published
Aug 6, 2025
Remotely exploitable denial of service in Rosenpass
Moderate
CVE-2023-53157
was published
for
rosenpass
(Rust)
Dec 21, 2023
Duplicate Advisory: Remotely exploitable denial of service in Rosenpass
Moderate
GHSA-624c-2h52-gf7f
was published
for
rosenpass
(Rust)
Jul 28, 2025
•
withdrawn
An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol...
High
Unreviewed
CVE-2025-52949
was published
Jul 11, 2025
Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header
Moderate
CVE-2025-53604
was published
for
web-push
(Rust)
Jul 5, 2025
Improper handling of length parameter inconsistency vulnerability in Mitsubishi Electric FA...
Critical
Unreviewed
CVE-2021-20588
was published
May 24, 2022
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a...
Moderate
Unreviewed
CVE-2025-23247
was published
May 27, 2025
rdiffweb's unlimited length email field can lead to DoS
High
CVE-2022-3272
was published
for
rdiffweb
(pip)
Sep 27, 2022
The communication framework module has a vulnerability of not truncating data properly.Successful...
High
Unreviewed
CVE-2022-41586
was published
Oct 14, 2022
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The...
Moderate
Unreviewed
CVE-2025-29931
was published
Apr 17, 2025
In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR...
Low
Unreviewed
CVE-2025-32366
was published
Apr 7, 2025
ProTip!
Advisories are also available from the
GraphQL API