GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
59 advisories
Filter by severity
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
Critical
CVE-2026-55209
was published
for
resdata
(pip)
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
High
CVE-2026-73564
was published
for
github.com/fatedier/frp
(Go)
Jul 24, 2026
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Moderate
CVE-2026-73489
was published
for
russh
(Rust)
Jul 24, 2026
GoBGP confederation validation panics on empty AS_PATH attribute
Moderate
CVE-2026-49838
was published
for
github.com/osrg/gobgp/v4
(Go)
Jul 9, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
Moderate
GHSA-3ccm-4qq2-5wrp
was published
for
github.com/edgelesssys/contrast
(Go)
Jul 1, 2026
golang.org/x/crypto: Invoking pathological inputs can lead to client panic
Moderate
CVE-2026-46598
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
High
CVE-2026-46377
was published
for
github.com/tomwright/dasel/v3
(Go)
May 19, 2026
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
High
CVE-2026-45799
was published
for
com.squareup.wire:wire-runtime
(Maven)
May 19, 2026
ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.
Moderate
CVE-2026-45624
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define
Moderate
CVE-2026-45359
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
Moderate
CVE-2026-44310
was published
for
github.com/sigstore/gitsign
(Go)
May 8, 2026
vLLM Vulnerable to Remote DoS via Special-Token Placeholders
Moderate
CVE-2026-44222
was published
for
vllm
(pip)
May 5, 2026
Incus Vulnerable to Panic via Snapshot Bounds Check
High
CVE-2026-40251
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
May 4, 2026
GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
High
CVE-2026-41643
was published
for
github.com/osrg/gobgp/v4
(Go)
Apr 29, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
High
CVE-2026-40886
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Apr 23, 2026
Step CA affected by an index out of bounds panic in TPM attestation EKU validation
Low
CVE-2026-40097
was published
for
github.com/smallstep/certificates
(Go)
Apr 10, 2026
Wasmtime: Panic when transcoding misaligned utf-16 strings
Moderate
CVE-2026-34942
was published
for
wasmtime
(Rust)
Apr 9, 2026
EnhancedLinq.Async is Vulnerable to Denial of Service via Transitive Dependency Microsoft.Bcl.Memory
High
GHSA-32wq-ppwg-3w4m
was published
for
EnhancedLinq.Async
(NuGet)
Apr 1, 2026
go-git missing validation decoding Index v4 files leads to panic
Low
CVE-2026-33762
was published
for
github.com/go-git/go-git/v5
(Go)
Mar 30, 2026
Packetbeat does not properly validate an array index in multiple protocol parser components
Moderate
CVE-2026-26933
was published
for
github.com/elastic/beats/v7
(Go)
Mar 19, 2026
Ella Core panics on invalid PDU Session IDs in NGAP messages
Moderate
CVE-2026-33281
was published
for
github.com/ellanetworks/core
(Go)
Mar 19, 2026
Duplicate Advisory: pgproto3: Negative field length panics in DataRow.Decode
High
CVE-2026-4427
was published
for
github.com/jackc/pgproto3/v2
(Go)
Mar 19, 2026
•
withdrawn
gosaml2 CBC Padding Panic — Unauthenticated Process Crash
High
GHSA-hwqm-qvj9-4jr2
was published
for
github.com/russellhaering/gosaml2
(Go)
Mar 18, 2026
Out-of-Bounds Slice Access in free5GC CHF Leading to DoS
High
CVE-2026-32937
was published
for
github.com/free5gc/chf
(Go)
Mar 18, 2026
ProTip!
Advisories are also available from the
GraphQL API