GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
79 advisories
Filter by severity
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
High
CVE-2026-50131
was published
for
@fedify/fedify
(npm)
Jul 14, 2026
An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of...
High
Unreviewed
CVE-2026-57026
was published
Jul 10, 2026
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
Moderate
CVE-2026-55767
was published
for
guzzlehttp/guzzle
(Composer)
Jun 19, 2026
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
High
CVE-2026-48059
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jun 11, 2026
On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can...
High
Unreviewed
CVE-2025-8873
was published
Jun 5, 2026
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a...
High
Unreviewed
CVE-2019-25720
was published
Jun 3, 2026
Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling...
Moderate
Unreviewed
CVE-2019-25723
was published
Jun 2, 2026
Dräger Atlan A350 software versions 1.00 through 1.01 contains an improper input handling...
Moderate
Unreviewed
CVE-2021-4479
was published
Jun 2, 2026
Memory corruption while processing fastboot OEM commands.
High
Unreviewed
CVE-2026-24087
was published
Jun 2, 2026
Memory corruption while processing fastboot commands with invalid input.
High
Unreviewed
CVE-2026-24089
was published
Jun 2, 2026
Memory corruption while processing fastboot commands with improperly formatted input.
High
Unreviewed
CVE-2026-24091
was published
Jun 2, 2026
Memory Corruption when processing fastboot commands to set display mode.
High
Unreviewed
CVE-2026-24092
was published
Jun 2, 2026
XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker...
Moderate
Unreviewed
CVE-2026-10099
was published
May 29, 2026
Keycloak: Denial of Service via specially crafted SAML input
High
CVE-2026-7307
was published
for
org.keycloak:keycloak-saml-core
(Maven)
May 19, 2026
Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and...
High
Unreviewed
CVE-2026-0983
was published
May 18, 2026
Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25...
High
Unreviewed
CVE-2026-6442
was published
Apr 16, 2026
Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow...
High
Unreviewed
CVE-2026-40198
was published
Apr 11, 2026
An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used...
High
Unreviewed
CVE-2026-33778
was published
Apr 10, 2026
Rack::Request accepts invalid Host characters, enabling host allowlist bypass
Moderate
CVE-2026-34835
was published
for
rack
(RubyGems)
Apr 2, 2026
A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could...
Moderate
Unreviewed
CVE-2026-20114
was published
Mar 25, 2026
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one...
Moderate
Unreviewed
CVE-2025-13995
was published
Mar 19, 2026
A flaw was found in libsoup, a library used by applications to send network requests. This...
Low
Unreviewed
CVE-2026-3632
was published
Mar 17, 2026
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
High
Unreviewed
CVE-2026-25679
was published
Mar 7, 2026
Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows...
Moderate
Unreviewed
CVE-2025-59785
was published
Mar 4, 2026
uv has ZIP payload obfuscation through parsing differentials
Moderate
CVE-2025-13327
was published
for
uv
(Rust)
Feb 27, 2026
ProTip!
Advisories are also available from the
GraphQL API