GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
132 advisories
Filter by severity
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component,...
Moderate
Unreviewed
CVE-2026-18728
was published
Aug 13, 2026
A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer...
Moderate
Unreviewed
CVE-2026-18727
was published
Aug 13, 2026
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an...
Moderate
Unreviewed
CVE-2026-73433
was published
Aug 12, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability...
Moderate
Unreviewed
CVE-2026-71389
was published
Aug 11, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability...
Moderate
Unreviewed
CVE-2026-48435
was published
Aug 11, 2026
Information Disclosure when processing wireless network channel switch information with...
Moderate
Unreviewed
CVE-2026-24077
was published
Aug 4, 2026
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
Moderate
CVE-2026-54345
was published
for
github.com/gopacket/gopacket
(Go)
Jul 28, 2026
[This CNA information record relates to multiple CVEs; the
text explains which aspects...
Moderate
Unreviewed
CVE-2026-42495
was published
Jul 28, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability...
Moderate
Unreviewed
CVE-2026-48298
was published
Jul 15, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability...
Moderate
Unreviewed
CVE-2026-48296
was published
Jul 15, 2026
FatFs R0.16 and earlier exhibits a stale dirty-cache skip via unsigned-subtraction wrap in f_read...
Moderate
Unreviewed
CVE-2026-6685
was published
Jul 1, 2026
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in...
Moderate
Unreviewed
CVE-2026-58058
was published
Jun 28, 2026
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Reject zero...
Moderate
Unreviewed
CVE-2026-53150
was published
Jun 25, 2026
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in...
Moderate
Unreviewed
CVE-2026-11850
was published
Jun 11, 2026
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned...
Moderate
Unreviewed
CVE-2026-11789
was published
Jun 9, 2026
In the Linux kernel, the following vulnerability has been resolved:
apparmor: avoid per-cpu hold...
Moderate
Unreviewed
CVE-2026-45884
was published
May 27, 2026
ImageMagick: Heap Buffer Over-Read in IPTC encoder
Moderate
CVE-2026-42326
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow ...
Moderate
Unreviewed
CVE-2026-34667
was published
May 12, 2026
CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow ...
Moderate
Unreviewed
CVE-2026-34672
was published
May 12, 2026
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix transaction abort...
Moderate
Unreviewed
CVE-2026-43359
was published
May 8, 2026
In the Linux kernel, the following vulnerability has been resolved:
media: chips-media: wave5:...
Moderate
Unreviewed
CVE-2026-43301
was published
May 8, 2026
GoBGP has an Integer Underflow Issue
Moderate
CVE-2026-7736
was published
for
github.com/osrg/gobgp/v4
(Go)
May 4, 2026
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of...
Moderate
Unreviewed
CVE-2026-40356
was published
Apr 28, 2026
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_ncm: validate...
Moderate
Unreviewed
CVE-2026-31617
was published
Apr 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: Fix...
Moderate
Unreviewed
CVE-2026-31551
was published
Apr 24, 2026
ProTip!
Advisories are also available from the
GraphQL API