GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
443 advisories
Filter by severity
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service...
High
Unreviewed
CVE-2026-17177
was published
Aug 14, 2026
A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the...
Moderate
Unreviewed
CVE-2026-72683
was published
Aug 13, 2026
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request...
Moderate
Unreviewed
CVE-2026-72686
was published
Aug 13, 2026
Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern...
Moderate
Unreviewed
CVE-2026-72679
was published
Aug 13, 2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized...
Moderate
Unreviewed
CVE-2026-72647
was published
Aug 13, 2026
Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a...
Moderate
Unreviewed
CVE-2026-72636
was published
Aug 13, 2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data...
Moderate
Unreviewed
CVE-2026-72638
was published
Aug 13, 2026
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library...
Critical
Unreviewed
CVE-2026-32327
was published
Aug 6, 2026
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an...
Moderate
Unreviewed
CVE-2026-15996
was published
Aug 5, 2026
** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy.
This issue...
High
Unreviewed
CVE-2026-61483
was published
Aug 5, 2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError...
High
Unreviewed
CVE-2026-68073
was published
Aug 5, 2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError...
High
Unreviewed
CVE-2026-67590
was published
Aug 5, 2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError...
High
Unreviewed
CVE-2026-66274
was published
Aug 5, 2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError...
High
Unreviewed
CVE-2026-67552
was published
Aug 5, 2026
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
GeoDjango's `django...
Moderate
Unreviewed
CVE-2026-15830
was published
Aug 4, 2026
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard....
High
Unreviewed
CVE-2026-13506
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self...
High
Unreviewed
CVE-2026-59645
was published
Aug 3, 2026
axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing...
Moderate
Unreviewed
CVE-2026-67321
was published
Aug 1, 2026
Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to...
High
Unreviewed
CVE-2026-67194
was published
Jul 29, 2026
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an...
High
Unreviewed
CVE-2026-67215
was published
Jul 29, 2026
The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs...
High
Unreviewed
CVE-2026-58178
was published
Jul 29, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of...
High
Unreviewed
CVE-2026-16192
was published
Jul 28, 2026
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Validate...
High
Unreviewed
CVE-2026-64219
was published
Jul 24, 2026
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Moderate
GHSA-r292-9mhp-454m
was published
for
tar
(npm)
Jul 24, 2026
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
Moderate
CVE-2026-55594
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API