GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
759 advisories
Filter by severity
ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
Moderate
CVE-2026-101912
was published
for
ip-address
(npm)
Sep 29, 2026
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-102321
was published
Sep 29, 2026
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-102328
was published
Sep 29, 2026
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-102323
was published
Sep 29, 2026
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-102326
was published
Sep 29, 2026
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-102299
was published
Sep 29, 2026
Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging...
High
Unreviewed
CVE-2026-95380
was published
Sep 29, 2026
Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to...
High
Unreviewed
CVE-2026-95365
was published
Sep 29, 2026
Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to...
High
Unreviewed
CVE-2026-95286
was published
Sep 29, 2026
A flaw was found in libsoup. When handling an incoming WebSocket Pong frame,...
High
Unreviewed
CVE-2026-102556
was published
Sep 29, 2026
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended...
High
Unreviewed
CVE-2026-97737
was published
Sep 25, 2026
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup...
Critical
Unreviewed
CVE-2026-94083
was published
Sep 20, 2026
Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging...
High
Unreviewed
CVE-2026-93377
was published
Sep 17, 2026
Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker...
High
Unreviewed
CVE-2026-91731
was published
Sep 15, 2026
Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker...
High
Unreviewed
CVE-2026-91741
was published
Sep 15, 2026
Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker...
High
Unreviewed
CVE-2026-91715
was published
Sep 15, 2026
Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker...
High
Unreviewed
CVE-2026-91709
was published
Sep 15, 2026
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.7 and...
Moderate
Unreviewed
CVE-2026-84602
was published
Sep 14, 2026
A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS...
Moderate
Unreviewed
CVE-2026-84635
was published
Sep 14, 2026
A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27,...
High
Unreviewed
CVE-2026-84563
was published
Sep 14, 2026
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26...
Moderate
Unreviewed
CVE-2026-65409
was published
Sep 14, 2026
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit...
Critical
Unreviewed
CVE-2026-71644
was published
Sep 11, 2026
Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...
High
Unreviewed
CVE-2026-87636
was published
Sep 9, 2026
Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-87612
was published
Sep 9, 2026
Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read...
Moderate
Unreviewed
CVE-2026-87564
was published
Sep 9, 2026
ProTip!
Advisories are also available from the
GraphQL API