Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

195 advisories

Loading
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow Critical
CVE-2026-77408 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799) High
CVE-2026-63126 was published for com.squareup.wire:wire-runtime (Maven) Sep 17, 2026
thientd Credited to thientd and gladiator9797 gladiator9797 gladiator9797
rclone local: crafted Range request against a translated symlink panics (DoS) Moderate
CVE-2026-88015 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
vLLM: Cross-User Data Leak Vulnerability Moderate
CVE-2026-73558 was published for vllm (pip) Sep 8, 2026
songlh Credited to songlh, molly-ting, and jperezdealgaba molly-ting molly-ting
jperezdealgaba jperezdealgaba
nanoid: Integer Overflow or Wraparound High
CVE-2026-73086 was published for nanoid (npm) Sep 1, 2026
alanzabihi Credited to alanzabihi
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply High
CVE-2026-55764 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) Critical
CVE-2026-54755 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash Moderate
CVE-2026-61799 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
sondt99 Credited to sondt99
New API: Integer overflow in quota billing yields negative charges (self-crediting) Critical
CVE-2026-71479 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
lihui12388 Credited to lihui12388 and Calcium-Ion Calcium-Ion Calcium-Ion
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability High
CVE-2026-62897 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability High
CVE-2026-62886 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow Moderate
CVE-2026-53466 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 31, 2026
Bin-infinite Credited to Bin-infinite
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow High
CVE-2026-73564 was published for github.com/fatedier/frp (Go) Jul 24, 2026
arkmarta Credited to arkmarta
kongzhenhit-code Credited to kongzhenhit-code
ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided Moderate
CVE-2026-62343 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
Kwstubbs Credited to Kwstubbs
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS High
CVE-2026-59879 was published for immutable (npm) Jul 21, 2026
mateuszismyname Credited to mateuszismyname, jdeniau, ravali-ch15, domcleal, LeongXuhua, and Ryan-Leber jdeniau jdeniau
ravali-ch15 ravali-ch15 domcleal domcleal LeongXuhua LeongXuhua Ryan-Leber Ryan-Leber
Serotav Credited to Serotav and radarhere radarhere radarhere
Serotav Credited to Serotav and radarhere radarhere radarhere
jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow High
CVE-2026-52834 was published for jxl-grid (Rust) Jul 2, 2026
jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow Moderate
GHSA-66m8-c62j-h6v5 was published for jxl-oxide (Rust) Jul 2, 2026
jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS) Moderate
GHSA-2v8p-fqpx-2q3w was published for jxl-modular (Rust) Jul 2, 2026
impost0r Credited to impost0r
golang.org/x/crypto vulnerable to infinite loop on large channel writes Critical
CVE-2026-39834 was published for golang.org/x/crypto (Go) Jun 25, 2026
AArnott Credited to AArnott
Oj: Integer Overflow in Oj.load 2GB String Handling High
CVE-2026-54903 was published for oj (RubyGems) Jun 19, 2026
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` Moderate
GHSA-5prr-v3j2-97mh was published for nokogiri (RubyGems) Jun 19, 2026
cla7aye15I4nd Credited to cla7aye15I4nd
ProTip! Advisories are also available from the GraphQL API