GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,818
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,355
Swift
54
Unreviewed advisories
All unreviewed
5,000+
19 advisories
Filter by severity
protobufjs has overlong UTF-8 decoding
Moderate
CVE-2026-44288
was published
for
@protobufjs/utf8
(npm)
May 12, 2026
uutils coreutils has an Improper Handling of Unicode Encoding Issue
Low
CVE-2026-35373
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Improper Handling of Unicode Encoding Issue
Low
CVE-2026-35375
was published
for
coreutils
(Rust)
Apr 22, 2026
coreutils' comm utility silently corrupts data by performing lossy UTF-8 conversion on all output lines
Low
CVE-2026-35346
was published
for
coreutils
(Rust)
Apr 22, 2026
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform...
Moderate
Unreviewed
CVE-2026-20202
was published
Apr 15, 2026
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote...
High
Unreviewed
CVE-2026-4116
was published
Apr 9, 2026
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote...
Moderate
Unreviewed
CVE-2026-4114
was published
Apr 9, 2026
OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists
Moderate
GHSA-392f-ggf5-fp3c
was published
for
openclaw
(npm)
Mar 2, 2026
Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
Moderate
CVE-2026-25480
was published
for
litestar
(pip)
Feb 9, 2026
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
High
CVE-2026-23950
was published
for
tar
(npm)
Jan 21, 2026
HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive...
Moderate
Unreviewed
CVE-2025-55129
was published
Dec 2, 2025
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path...
High
Unreviewed
CVE-2024-43093
was published
Nov 13, 2024
In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode ...
Moderate
Unreviewed
CVE-2024-8067
was published
Sep 25, 2024
Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side...
Unknown
Unreviewed
CVE-2017-20190
was published
Mar 27, 2024
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and...
Critical
Unreviewed
CVE-2024-24691
was published
Feb 14, 2024
ewen-lbh/ffcss Late-Unicode normalization vulnerability
Moderate
CVE-2023-52081
was published
for
github.com/ewen-lbh/ffcss
(Go)
Dec 28, 2023
An Improper Handling of Unicode Encoding vulnerability in the Schweitzer Engineering...
Moderate
Unreviewed
CVE-2023-31169
was published
Aug 31, 2023
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI...
Critical
Unreviewed
CVE-2023-39213
was published
Aug 9, 2023
Ciphertext Malleability Issue in Tink Java
Moderate
CVE-2020-8929
was published
for
com.google.crypto.tink:tink
(Maven)
Oct 16, 2020
ProTip!
Advisories are also available from the
GraphQL API