GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
12,882 advisories
Filter by severity
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0...
Critical
Unreviewed
CVE-2026-67330
was published
Aug 1, 2026
GitPython before 3.1.50 fails to validate newline characters in the section parameter of...
High
Unreviewed
CVE-2026-67326
was published
Aug 1, 2026
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel...
High
Unreviewed
CVE-2026-67296
was published
Aug 1, 2026
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Moderate
CVE-2026-54909
was published
for
github.com/pion/stun
(Go)
Jul 31, 2026
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
Moderate
CVE-2026-53551
was published
for
github.com/free5gc/ausf
(Go)
Jul 31, 2026
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
High
CVE-2026-53503
was published
for
thumbor
(pip)
Jul 31, 2026
HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to...
Moderate
Unreviewed
CVE-2025-62347
was published
Jul 31, 2026
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Moderate
CVE-2026-65834
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
A flaw was found in the keycloak-services component of Keycloak, which provides identity and...
Low
Unreviewed
CVE-2026-18206
was published
Jul 31, 2026
A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and...
Low
Unreviewed
CVE-2026-18217
was published
Jul 31, 2026
A flaw was found in the secure-client-uris client policy executor within Keycloak core services....
Moderate
Unreviewed
CVE-2026-18211
was published
Jul 31, 2026
Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72...
Critical
Unreviewed
CVE-2026-18002
was published
Jul 30, 2026
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-18009
was published
Jul 30, 2026
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-18014
was published
Jul 30, 2026
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17970
was published
Jul 30, 2026
Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17982
was published
Jul 30, 2026
Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922...
Critical
Unreviewed
CVE-2026-17987
was published
Jul 30, 2026
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17988
was published
Jul 30, 2026
Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed...
Critical
Unreviewed
CVE-2026-17991
was published
Jul 30, 2026
Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72...
Critical
Unreviewed
CVE-2026-17990
was published
Jul 30, 2026
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17926
was published
Jul 30, 2026
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17929
was published
Jul 30, 2026
Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android...
Critical
Unreviewed
CVE-2026-17940
was published
Jul 30, 2026
Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72...
Moderate
Unreviewed
CVE-2026-17955
was published
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API