GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
71 advisories
Filter by severity
rclone local: crafted Range request against a translated symlink panics (DoS)
Moderate
CVE-2026-88015
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
vLLM: Cross-User Data Leak Vulnerability
Moderate
CVE-2026-73558
was published
for
vllm
(pip)
Sep 8, 2026
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
Moderate
CVE-2026-61799
was published
for
io.netty.incubator:netty-incubator-codec-bhttp
(Maven)
Aug 20, 2026
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
Moderate
CVE-2026-53466
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 31, 2026
ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
Moderate
CVE-2026-62946
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided
Moderate
CVE-2026-62343
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow
Moderate
GHSA-66m8-c62j-h6v5
was published
for
jxl-oxide
(Rust)
Jul 2, 2026
jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)
Moderate
GHSA-2v8p-fqpx-2q3w
was published
for
jxl-modular
(Rust)
Jul 2, 2026
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
Moderate
GHSA-5prr-v3j2-97mh
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load
Moderate
CVE-2026-55093
was published
for
tract-nnef
(Rust)
Jun 18, 2026
NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation
Moderate
CVE-2026-55254
was published
for
NCalc.Core
(NuGet)
Jun 18, 2026
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing
Moderate
CVE-2026-54697
was published
for
org.connectbot.sshlib:sshlib
(Maven)
Jun 12, 2026
Microsoft DirectX12: .spritefont multiply overflow only in 32-bit builds
Moderate
GHSA-5r97-79vw-qvm4
was published
for
directxtk12_desktop_win10
(NuGet)
May 18, 2026
Microsoft DirectX: .spritefont multiply overflow only in 32-bit builds
Moderate
GHSA-c55g-rp4x-fx84
was published
for
directxtk_desktop_win10
(NuGet)
May 18, 2026
imageproc: integer overflow in kernel size check leads to out-of-bounds read
Moderate
GHSA-w5p8-4jcx-2j6r
was published
for
imageproc
(Rust)
May 7, 2026
imageproc: Out-of-bounds read via NaN coordinates in bilinear/bicubic sampling
Moderate
GHSA-qg8r-f7x3-25f7
was published
for
imageproc
(Rust)
May 7, 2026
imageproc has fragile bounds check when sampling from image
Moderate
GHSA-5qv7-j6w5-fr4m
was published
for
imageproc
(Rust)
May 7, 2026
Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing
Moderate
CVE-2026-42580
was published
for
io.netty:netty-codec-http
(Maven)
May 7, 2026
kanidmd_lib: Image upload validators run before authorization; PNG validator panics on malformed input
Moderate
GHSA-84jc-3hj2-hwc7
was published
for
kanidmd_lib
(Rust)
May 6, 2026
Pillow has an integer overflow when processing fonts
Moderate
CVE-2026-42308
was published
for
pillow
(pip)
May 4, 2026
Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior
Moderate
CVE-2026-42199
was published
for
grid
(Rust)
Apr 24, 2026
go-ntlmssp NTLM challenges can panic on malformed payloads
Moderate
CVE-2026-32952
was published
for
github.com/Azure/go-ntlmssp
(Go)
Apr 23, 2026
ImageMagick has an integer overflow in despeckle operation causing a heap buffer overflow on 32-bit builds
Moderate
CVE-2026-34238
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 13, 2026
ImageMagick has a heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit builds
Moderate
CVE-2026-33900
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 13, 2026
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT vulnerable to Integer Overflow or Wraparound
Moderate
CVE-2026-40046
was published
for
org.apache.activemq:activemq-all
(Maven)
Apr 9, 2026
ProTip!
Advisories are also available from the
GraphQL API