GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,086 advisories
Filter by severity
vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when...
Moderate
Unreviewed
CVE-2026-90554
was published
Sep 12, 2026
Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where...
High
Unreviewed
CVE-2026-89147
was published
Sep 11, 2026
An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42...
High
Unreviewed
CVE-2026-71647
was published
Sep 11, 2026
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
High
GHSA-m3wp-48jr-vr4g
was published
for
mistralrs-server-core
(Rust)
Sep 10, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by...
Moderate
Unreviewed
CVE-2026-9338
was published
Sep 10, 2026
Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener...
Moderate
Unreviewed
CVE-2026-87106
was published
Sep 10, 2026
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
High
CVE-2026-59161
was published
for
github.com/xuri/excelize
(Go)
Sep 10, 2026
GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR...
High
Unreviewed
CVE-2026-88290
was published
Sep 10, 2026
GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated...
High
Unreviewed
CVE-2026-88286
was published
Sep 10, 2026
A vulnerability in the web-based management interface of CPPM could allow an unauthenticated...
High
Unreviewed
CVE-2026-73786
was published
Sep 9, 2026
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
Moderate
CVE-2026-53495
was published
for
github.com/containerd/containerd
(Go)
Sep 9, 2026
PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing...
High
Unreviewed
CVE-2026-86201
was published
Sep 9, 2026
PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket...
High
Unreviewed
CVE-2026-86204
was published
Sep 9, 2026
PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing,...
Moderate
Unreviewed
CVE-2025-71418
was published
Sep 9, 2026
Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead...
Moderate
Unreviewed
CVE-2026-82001
was published
Sep 8, 2026
ColdFusion is affected by an Uncontrolled Resource Consumption vulnerability that could lead to...
Moderate
Unreviewed
CVE-2026-76000
was published
Sep 8, 2026
In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of...
Moderate
Unreviewed
CVE-2026-28596
was published
Sep 8, 2026
In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource...
Moderate
Unreviewed
CVE-2026-28617
was published
Sep 8, 2026
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
High
GHSA-2x7j-588g-ccc2
was published
for
nodemailer
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
High
CVE-2026-77037
was published
for
multer
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via oversized array index in field names
High
CVE-2026-82333
was published
for
multer
(npm)
Sep 8, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
High
CVE-2026-84375
was published
for
js-yaml
(npm)
Sep 8, 2026
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
High
GHSA-j95f-988m-3j2f
was published
for
@tiptap/core
(npm)
Sep 8, 2026
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
Moderate
CVE-2026-84364
was published
for
hono
(npm)
Sep 8, 2026
xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser
High
CVE-2026-83619
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API