GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,038 advisories
Filter by severity
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
Moderate
CVE-2026-73556
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
Moderate
CVE-2026-71486
was published
for
vllm
(pip)
Sep 4, 2026
A flaw has been found in ramon-victor freegpt-webui up to...
Moderate
Unreviewed
CVE-2026-85703
was published
Sep 4, 2026
Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service...
High
Unreviewed
CVE-2021-44320
was published
Sep 4, 2026
IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie...
Moderate
Unreviewed
CVE-2026-19645
was published
Sep 4, 2026
SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request...
High
Unreviewed
CVE-2026-85585
was published
Sep 4, 2026
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer:...
High
Unreviewed
CVE-2026-85443
was published
Sep 4, 2026
A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the...
Moderate
Unreviewed
CVE-2026-85107
was published
Sep 3, 2026
A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability...
Low
Unreviewed
CVE-2026-85100
was published
Sep 3, 2026
A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability...
Moderate
Unreviewed
CVE-2026-84886
was published
Sep 3, 2026
A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects...
Low
Unreviewed
CVE-2026-84888
was published
Sep 3, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection
High
CVE-2026-67445
was published
for
github.com/axllent/mailpit
(Go)
Sep 2, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling
High
CVE-2026-67446
was published
for
github.com/axllent/mailpit
(Go)
Sep 2, 2026
A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the...
Moderate
Unreviewed
CVE-2026-84857
was published
Sep 2, 2026
A vulnerability was found in ntegrals openbrowser up to 067fc45d649baa961750da8e2f4a75d87c5c75c8....
Low
Unreviewed
CVE-2026-84833
was published
Sep 2, 2026
An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026...
Moderate
Unreviewed
CVE-2026-19475
was published
Sep 2, 2026
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
High
CVE-2026-82397
was published
for
tornado
(pip)
Sep 2, 2026
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
Moderate
CVE-2026-81723
was published
for
nltk
(pip)
Sep 2, 2026
A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects...
Low
Unreviewed
CVE-2026-84289
was published
Sep 2, 2026
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
High
CVE-2026-84304
was published
for
google.golang.org/grpc
(Go)
Sep 1, 2026
Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a...
Moderate
Unreviewed
CVE-2026-73759
was published
Sep 1, 2026
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX....
High
Unreviewed
CVE-2026-73773
was published
Sep 1, 2026
Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful...
Moderate
Unreviewed
CVE-2026-73754
was published
Sep 1, 2026
A denial-of-service vulnerability exists in the web-based management interface of HPE Networking...
Low
Unreviewed
CVE-2026-73744
was published
Sep 1, 2026
A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could...
Low
Unreviewed
CVE-2026-73746
was published
Sep 1, 2026
ProTip!
Advisories are also available from the
GraphQL API