GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
708 advisories
Filter by severity
A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise...
High
Unreviewed
CVE-2026-19118
was published
Sep 2, 2026
A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU...
Critical
Unreviewed
CVE-2026-78319
was published
Sep 1, 2026
Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit...
High
Unreviewed
CVE-2026-78422
was published
Aug 31, 2026
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
Critical
CVE-2026-54754
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows...
Low
Unreviewed
CVE-2026-82238
was published
Aug 28, 2026
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
High
GHSA-mf7q-r4rv-jv94
was published
for
github.com/crossplane/crossplane-runtime/v2
(Go)
Aug 27, 2026
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating...
High
Unreviewed
CVE-2026-65183
was published
Aug 26, 2026
Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who...
Moderate
Unreviewed
CVE-2026-79267
was published
Aug 25, 2026
Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to...
High
Unreviewed
CVE-2026-79263
was published
Aug 25, 2026
Race condition in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-79196
was published
Aug 25, 2026
Race condition in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
High
Unreviewed
CVE-2026-79155
was published
Aug 25, 2026
Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65...
Moderate
Unreviewed
CVE-2026-79089
was published
Aug 25, 2026
Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local...
High
Unreviewed
CVE-2026-79057
was published
Aug 25, 2026
Race condition in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had...
High
Unreviewed
CVE-2026-79071
was published
Aug 25, 2026
Race condition in Permissions in Google Chrome on on Android prior to 152.0.7977.65 allowed a...
Moderate
Unreviewed
CVE-2026-79046
was published
Aug 25, 2026
Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-78991
was published
Aug 25, 2026
Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2026-79017
was published
Aug 25, 2026
Race condition in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who...
Low
Unreviewed
CVE-2026-78894
was published
Aug 25, 2026
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
Moderate
CVE-2026-55535
was published
for
PraisonAI
(pip)
Aug 25, 2026
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
High
CVE-2026-55537
was published
for
PraisonAI
(pip)
Aug 25, 2026
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
High
CVE-2026-55524
was published
for
praisonaiagents
(pip)
Aug 25, 2026
Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook...
Moderate
Unreviewed
CVE-2026-56708
was published
Aug 25, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated...
High
Unreviewed
CVE-2026-16935
was published
Aug 21, 2026
Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to...
High
Unreviewed
CVE-2026-76020
was published
Aug 20, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root...
High
Unreviewed
CVE-2026-16927
was published
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API