GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,836 advisories
Filter by severity
The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed...
High
Unreviewed
CVE-2026-102762
was published
Sep 29, 2026
An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests...
High
Unreviewed
CVE-2026-102716
was published
Sep 29, 2026
IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18...
Moderate
Unreviewed
CVE-2026-95395
was published
Sep 29, 2026
Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default...
Moderate
Unreviewed
CVE-2026-102005
was published
Sep 28, 2026
In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process...
Moderate
Unreviewed
CVE-2026-102006
was published
Sep 28, 2026
Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every...
Critical
Unreviewed
CVE-2026-87078
was published
Sep 22, 2026
vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when...
High
Unreviewed
CVE-2026-94627
was published
Sep 22, 2026
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference...
High
Unreviewed
CVE-2026-93436
was published
Sep 18, 2026
Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on...
High
Unreviewed
CVE-2026-92230
was published
Sep 17, 2026
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
High
CVE-2026-63128
was published
for
rmcp
(Rust)
Sep 16, 2026
A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance ...
High
Unreviewed
CVE-2026-20222
was published
Sep 16, 2026
A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity...
High
Unreviewed
CVE-2026-18212
was published
Sep 16, 2026
A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS...
High
Unreviewed
CVE-2026-81563
was published
Sep 16, 2026
Http4s: DigestAuth nonce map grows unbounded
High
CVE-2026-69208
was published
for
org.http4s:http4s-ember-server_2.12
(Maven)
Sep 15, 2026
A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a...
Low
Unreviewed
CVE-2026-91926
was published
Sep 15, 2026
A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the...
Moderate
Unreviewed
CVE-2026-90784
was published
Sep 14, 2026
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that...
Low
Unreviewed
CVE-2026-78124
was published
Sep 11, 2026
libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective...
Low
Unreviewed
CVE-2026-78127
was published
Sep 11, 2026
strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in...
Low
Unreviewed
CVE-2026-78131
was published
Sep 11, 2026
Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized...
High
Unreviewed
CVE-2026-70065
was published
Sep 8, 2026
Missing release of memory after effective lifetime in Active Directory Domain Services allows an...
High
Unreviewed
CVE-2026-69809
was published
Sep 8, 2026
Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized...
Moderate
Unreviewed
CVE-2026-69781
was published
Sep 8, 2026
Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized...
High
Unreviewed
CVE-2026-69588
was published
Sep 8, 2026
Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized...
Moderate
Unreviewed
CVE-2026-69497
was published
Sep 8, 2026
Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized...
Moderate
Unreviewed
CVE-2026-69405
was published
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API