GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
5,040 advisories
Filter by severity
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device...
High
Unreviewed
CVE-2026-67304
was published
Aug 1, 2026
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache...
High
Unreviewed
CVE-2026-67288
was published
Aug 1, 2026
An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS)...
High
Unreviewed
CVE-2026-18064
was published
Jul 31, 2026
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI...
Critical
Unreviewed
CVE-2026-58161
was published
Jul 29, 2026
TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows...
High
Unreviewed
CVE-2026-67184
was published
Jul 28, 2026
Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows...
High
Unreviewed
CVE-2026-66749
was published
Jul 28, 2026
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
High
CVE-2026-47427
was published
for
github.com/github/github-mcp-server
(Go)
Jul 28, 2026
HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing...
Moderate
Unreviewed
CVE-2026-17574
was published
Jul 27, 2026
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
Moderate
GHSA-jpcw-4wr7-c3vq
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
Moderate
CVE-2026-59949
was published
for
at.yawk.lz4:lz4-java
(Maven)
Jul 24, 2026
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.
This...
High
Unreviewed
CVE-2026-45816
was published
Jul 24, 2026
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
Low
GHSA-qh5g-q395-cx4j
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a...
High
Unreviewed
CVE-2026-50032
was published
Jul 23, 2026
A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a...
Moderate
Unreviewed
CVE-2026-13070
was published
Jul 22, 2026
A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill...
High
Unreviewed
CVE-2026-13065
was published
Jul 22, 2026
In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set...
Moderate
Unreviewed
CVE-2026-55717
was published
Jul 22, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Low
CVE-2026-55984
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in...
Moderate
Unreviewed
CVE-2026-63762
was published
Jul 20, 2026
In the Linux kernel, the following vulnerability has been resolved:
nfsd: release layout stid on...
Critical
Unreviewed
CVE-2026-53399
was published
Jul 19, 2026
In the Linux kernel, the following vulnerability has been resolved:
fbdev: Fix fb_new_modelist...
Moderate
Unreviewed
CVE-2026-53403
was published
Jul 19, 2026
In the Linux kernel, the following vulnerability has been resolved:
NFSv4/flexfiles: reject zero...
High
Unreviewed
CVE-2026-53392
was published
Jul 19, 2026
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: reject non-VALID...
High
Unreviewed
CVE-2026-53383
was published
Jul 19, 2026
In the Linux kernel, the following vulnerability has been resolved:
NFSv4/pNFS: reject zero...
High
Unreviewed
CVE-2026-53391
was published
Jul 19, 2026
In the Linux kernel, the following vulnerability has been resolved:
media: vidtv: fix NULL...
Moderate
Unreviewed
CVE-2026-53382
was published
Jul 19, 2026
In the Linux kernel, the following vulnerability has been resolved:
vc_screen: fix null-ptr...
Moderate
Unreviewed
CVE-2026-53385
was published
Jul 19, 2026
ProTip!
Advisories are also available from the
GraphQL API