GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
100 advisories
Filter by severity
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
High
GHSA-pfvm-w89x-94jw
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
High
GHSA-jwjp-4649-v8jp
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)
High
CVE-2026-54632
was published
for
SIPSorcery
(NuGet)
Jul 28, 2026
Valibot: record() issue paths can make flatten() throw for inherited Object property names
Moderate
CVE-2026-59952
was published
for
valibot
(npm)
Jul 24, 2026
Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
Moderate
CVE-2026-59927
was published
for
mistune
(pip)
Jul 20, 2026
ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes
Moderate
CVE-2026-53496
was published
for
exifreader
(npm)
Jul 17, 2026
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
Moderate
CVE-2026-35339
was published
for
uu_chmod
(Rust)
Jul 6, 2026
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
Moderate
CVE-2026-54775
was published
for
CoreWCF.Kafka
(NuGet)
Jun 19, 2026
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
Low
CVE-2026-48524
was published
for
pyjwt
(pip)
Jun 15, 2026
@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
High
CVE-2026-48036
was published
for
@hulumi/drift
(npm)
Jun 10, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
CVE-2026-49235
was published
for
routinator
(Rust)
Jun 8, 2026
multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing
High
CVE-2026-8162
was published
for
multiparty
(npm)
May 18, 2026
Prometheus exporter process crash via malformed HTTP request
High
CVE-2026-44902
was published
for
@opentelemetry/auto-instrumentations-node
(npm)
May 11, 2026
free5GC NRF: type-confusion panic in POST /oauth2/token structured-form parser via Reflect.Set on incompatible types
High
CVE-2026-44325
was published
for
github.com/free5gc/nrf
(Go)
May 8, 2026
free5GC's NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)
High
CVE-2026-44319
was published
for
github.com/free5gc/nef
(Go)
May 8, 2026
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
High
GHSA-fpw6-hrg5-q5x5
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
rpassword affected by partial password reveal when input is interrupted
Low
GHSA-2p6r-x3vv-xqm2
was published
for
rpassword
(Rust)
May 6, 2026
Granian vulnerable to DoS via WSGI response header panic
Moderate
CVE-2026-42545
was published
for
granian
(pip)
May 6, 2026
nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals
High
CVE-2026-34065
was published
for
nimiq-primitives
(Rust)
Apr 22, 2026
justhtml includes multiple security fixes
Moderate
GHSA-c9vm-hv86-f23r
was published
for
justhtml
(pip)
Apr 10, 2026
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
Moderate
CVE-2026-40074
was published
for
@sveltejs/kit
(npm)
Apr 10, 2026
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future
Moderate
CVE-2026-27195
was published
for
wasmtime
(Rust)
Feb 24, 2026
Caddy: mTLS client authentication silently fails open when CA certificate file is missing or malformed
High
CVE-2026-27586
was published
for
github.com/caddyserver/caddy/v2
(Go)
Feb 24, 2026
ProTip!
Advisories are also available from the
GraphQL API