GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
711 advisories
Filter by severity
Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data...
Moderate
Unreviewed
CVE-2026-63140
was published
Jul 21, 2026
vLLM denial of service via prompt embeds on M-RoPE models
High
CVE-2026-55514
was published
for
vllm
(pip)
Jul 20, 2026
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2,...
High
Unreviewed
CVE-2025-56362
was published
Jul 15, 2026
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in...
High
Unreviewed
CVE-2025-56365
was published
Jul 15, 2026
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4,...
High
Unreviewed
CVE-2025-56361
was published
Jul 15, 2026
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an...
Moderate
Unreviewed
CVE-2026-47475
was published
Jul 14, 2026
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to...
Moderate
Unreviewed
CVE-2026-13122
was published
Jul 6, 2026
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update
High
CVE-2026-52829
was published
for
zebra-network
(Rust)
Jul 2, 2026
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers
Moderate
GHSA-c8w6-x74f-vmg3
was published
for
zebra-rpc
(Rust)
Jul 2, 2026
In the Linux kernel, the following vulnerability has been resolved:
blk-wbt: remove WARN_ON_ONCE...
Moderate
Unreviewed
CVE-2026-53319
was published
Jun 26, 2026
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Wrap DCN32...
Moderate
Unreviewed
CVE-2026-53285
was published
Jun 26, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: phonet: do not BUG_ON()...
Moderate
Unreviewed
CVE-2026-53292
was published
Jun 26, 2026
CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to...
Moderate
Unreviewed
CVE-2026-9718
was published
Jun 25, 2026
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that...
High
Unreviewed
CVE-2026-47145
was published
Jun 25, 2026
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that...
High
Unreviewed
CVE-2026-47146
was published
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
accel/ethosu: reject...
Moderate
Unreviewed
CVE-2026-53169
was published
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: validate group add...
Moderate
Unreviewed
CVE-2026-53039
was published
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
libceph: handle rbtree...
High
Unreviewed
CVE-2026-52954
was published
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
iommu: Fix WARN_ON in...
High
Unreviewed
CVE-2026-52952
was published
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix BUG_ON in...
Moderate
Unreviewed
CVE-2026-52961
was published
Jun 24, 2026
OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types
Moderate
CVE-2026-55776
was published
for
github.com/openbao/openbao
(Go)
Jun 19, 2026
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
High
CVE-2026-41523
was published
for
vllm
(pip)
Jun 16, 2026
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad....
Moderate
Unreviewed
CVE-2026-52718
was published
Jun 15, 2026
A vulnerability has been found in some Dahua products could allow an authenticated remote...
Moderate
Unreviewed
CVE-2026-29115
was published
Jun 10, 2026
A vulnerability has been found in some Dahua products could
allow an unauthenticated remote...
High
Unreviewed
CVE-2026-29116
was published
Jun 10, 2026
ProTip!
Advisories are also available from the
GraphQL API