GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
221 advisories
Filter by severity
Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.
A...
Unknown
Unreviewed
CVE-2026-102731
was published
Oct 2, 2026
Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket...
High
Unreviewed
CVE-2026-63574
was published
Oct 2, 2026
Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters...
High
Unreviewed
CVE-2026-103603
was published
Oct 2, 2026
Memory allocation with excessive size value in the DTLS handshake reassembly ...
High
Unreviewed
CVE-2026-63566
was published
Oct 2, 2026
A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with...
Moderate
Unreviewed
CVE-2026-42528
was published
Oct 1, 2026
devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
Low
GHSA-wf3x-273g-mvxv
was published
for
devalue
(npm)
Oct 1, 2026
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
High
CVE-2026-55149
was published
for
github.com/vouch/vouch-proxy
(Go)
Aug 20, 2026
pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)
Moderate
CVE-2026-102820
was published
for
pageant
(Rust)
Sep 30, 2026
PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2...
High
Unreviewed
CVE-2026-102809
was published
Sep 29, 2026
A pre-authentication attacker could leverage type size/count handling to cause excessive...
High
Unreviewed
CVE-2026-92550
was published
Sep 25, 2026
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as...
High
Unreviewed
CVE-2026-15567
was published
Aug 11, 2026
A user could provide an expression whose string length is longer than the...
Moderate
Unreviewed
CVE-2026-83530
was published
Sep 9, 2026
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1...
Moderate
Unreviewed
CVE-2026-96260
was published
Sep 22, 2026
KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub
Moderate
CVE-2026-62370
was published
for
github.com/kubeedge/kubeedge
(Go)
Sep 22, 2026
SIPGO: DoS via unvalidated WebSocket frame length
High
CVE-2026-77322
was published
for
github.com/emiago/sipgo
(Go)
Sep 22, 2026
SIPGO: DoS via unvalidated Content-Length in the stream parser
High
CVE-2026-58268
was published
for
github.com/emiago/sipgo
(Go)
Sep 22, 2026
psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry
High
CVE-2026-59991
was published
for
psd-tools
(pip)
Sep 22, 2026
vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI...
High
Unreviewed
CVE-2026-94626
was published
Sep 22, 2026
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
High
CVE-2026-77301
was published
for
adm-zip
(npm)
Sep 18, 2026
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation
High
CVE-2026-77410
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion
High
CVE-2026-85715
was published
for
exifreader
(npm)
Sep 17, 2026
GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the...
High
Unreviewed
CVE-2026-91752
was published
Sep 15, 2026
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software...
High
Unreviewed
CVE-2026-20295
was published
Sep 16, 2026
OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer
...
High
Unreviewed
CVE-2026-67211
was published
Sep 11, 2026
Description
The worker's Netty message decoder is installed ahead of the SASL authentication...
Critical
Unreviewed
CVE-2026-82435
was published
Sep 14, 2026
ProTip!
Advisories are also available from the
GraphQL API