GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
59 advisories
Filter by severity
vLLM: Cross-User Data Leak Vulnerability
Moderate
CVE-2026-73558
was published
for
vllm
(pip)
Sep 8, 2026
ExecuTorch integer overflow vulnerability
Critical
CVE-2025-30405
was published
for
executorch
(Maven)
Aug 8, 2025
ExecuTorch integer overflow vulnerability
Critical
CVE-2025-30404
was published
for
executorch
(Maven)
Aug 8, 2025
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
High
CVE-2026-59199
was published
for
Pillow
(pip)
Jul 20, 2026
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
High
CVE-2026-59197
was published
for
Pillow
(pip)
Jul 20, 2026
Pillow has an integer overflow when processing fonts
Moderate
CVE-2026-42308
was published
for
pillow
(pip)
May 4, 2026
Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
High
CVE-2026-42311
was published
for
pillow
(pip)
May 4, 2026
OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write
High
CVE-2026-34589
was published
for
OpenEXR
(pip)
Apr 8, 2026
OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
High
CVE-2026-34588
was published
for
OpenEXR
(pip)
Apr 8, 2026
OpenEXR: integer overflow to OOB write in uncompress_b44_impl()
High
CVE-2026-34544
was published
for
openexr
(pip)
Apr 3, 2026
UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
High
CVE-2026-32875
was published
for
ujson
(pip)
Mar 18, 2026
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
Moderate
CVE-2026-23833
was published
for
esphome
(pip)
Jan 21, 2026
Vyper vulnerable to integer overflow in loop
High
CVE-2023-32058
was published
for
vyper
(pip)
May 12, 2023
Integer overflow in TFLite array creation
High
CVE-2022-23558
was published
for
tensorflow
(pip)
Feb 9, 2022
Integer overflow leading to crash in Tensorflow
High
CVE-2022-21738
was published
for
tensorflow
(pip)
Feb 9, 2022
Memory exhaustion in Tensorflow
Moderate
CVE-2022-21733
was published
for
tensorflow
(pip)
Feb 10, 2022
Overflow and uncaught divide by zero in Tensorflow
High
CVE-2022-21729
was published
for
tensorflow
(pip)
Feb 10, 2022
ProTip!
Advisories are also available from the
GraphQL API