GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
180 advisories
Filter by severity
A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the ...
Moderate
Unreviewed
CVE-2026-71218
was published
Aug 11, 2026
GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src...
Moderate
Unreviewed
CVE-2026-66485
was published
Aug 10, 2026
Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in...
High
Unreviewed
CVE-2026-66733
was published
Aug 6, 2026
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
High
CVE-2026-71314
was published
for
nuxt
(npm)
Aug 5, 2026
imagecli's `scale <ratio>` pipeline operation (Scale::apply() in src/image_ops.rs) computes...
High
Unreviewed
CVE-2026-70377
was published
Aug 5, 2026
** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in...
High
Unreviewed
CVE-2026-61485
was published
Aug 5, 2026
A pre-authentication attacker could leverage type size/count handling to cause excessive...
High
Unreviewed
CVE-2026-66273
was published
Aug 5, 2026
pre-authentication attacker could leverage type size/count handling to cause excessive allocation...
High
Unreviewed
CVE-2026-67551
was published
Aug 5, 2026
A pre-authentication attacker could leverage type size/count handling to cause excessive...
High
Unreviewed
CVE-2026-67589
was published
Aug 5, 2026
SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that...
High
Unreviewed
CVE-2026-69702
was published
Aug 4, 2026
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.utils...
Moderate
Unreviewed
CVE-2026-15337
was published
Aug 4, 2026
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust...
High
Unreviewed
CVE-2026-58067
was published
Aug 4, 2026
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length...
High
Unreviewed
CVE-2026-12852
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a...
High
Unreviewed
CVE-2026-14682
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge...
High
Unreviewed
CVE-2026-58060
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by...
High
Unreviewed
CVE-2026-59649
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked...
High
Unreviewed
CVE-2026-59646
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before...
High
Unreviewed
CVE-2026-12185
was published
Aug 3, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Moderate
CVE-2026-52857
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
High
CVE-2026-54638
was published
for
github.com/gotd/td
(Go)
Jul 28, 2026
pypdf: Possible large memory usage for wrong image dimensions
Moderate
CVE-2026-59938
was published
for
pypdf
(pip)
Jul 23, 2026
Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF...
High
Unreviewed
CVE-2026-65315
was published
Jul 22, 2026
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an...
Moderate
Unreviewed
CVE-2026-59844
was published
Jul 21, 2026
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
High
CVE-2026-59204
was published
for
pillow
(pip)
Jul 20, 2026
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
High
CVE-2026-55380
was published
for
pillow
(pip)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API