GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
354 advisories
Filter by severity
A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise...
High
Unreviewed
CVE-2026-19118
was published
Sep 2, 2026
Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit...
High
Unreviewed
CVE-2026-78422
was published
Aug 31, 2026
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
High
GHSA-mf7q-r4rv-jv94
was published
for
github.com/crossplane/crossplane-runtime/v2
(Go)
Aug 27, 2026
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating...
High
Unreviewed
CVE-2026-65183
was published
Aug 26, 2026
Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to...
High
Unreviewed
CVE-2026-79263
was published
Aug 25, 2026
Race condition in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
High
Unreviewed
CVE-2026-79155
was published
Aug 25, 2026
Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local...
High
Unreviewed
CVE-2026-79057
was published
Aug 25, 2026
Race condition in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had...
High
Unreviewed
CVE-2026-79071
was published
Aug 25, 2026
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
High
CVE-2026-55537
was published
for
PraisonAI
(pip)
Aug 25, 2026
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
High
CVE-2026-55524
was published
for
praisonaiagents
(pip)
Aug 25, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated...
High
Unreviewed
CVE-2026-16935
was published
Aug 21, 2026
Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to...
High
Unreviewed
CVE-2026-76020
was published
Aug 20, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root...
High
Unreviewed
CVE-2026-16927
was published
Aug 20, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary...
High
Unreviewed
CVE-2026-16922
was published
Aug 20, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical...
High
Unreviewed
CVE-2026-16838
was published
Aug 19, 2026
Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of...
High
Unreviewed
CVE-2024-13942
was published
Aug 19, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of...
High
Unreviewed
CVE-2026-16819
was published
Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race...
High
Unreviewed
CVE-2026-56797
was published
Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU)...
High
Unreviewed
CVE-2026-53477
was published
Aug 19, 2026
During execve(2) of a SUID binary, the new virtual address space is installed before the process...
High
Unreviewed
CVE-2026-49415
was published
Aug 19, 2026
Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had...
High
Unreviewed
CVE-2026-76044
was published
Aug 18, 2026
n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the...
High
Unreviewed
CVE-2026-71539
was published
Aug 18, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized...
High
Unreviewed
CVE-2026-16967
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized...
High
Unreviewed
CVE-2026-16896
was published
Aug 13, 2026
A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an...
High
Unreviewed
CVE-2026-72584
was published
Aug 10, 2026
ProTip!
Advisories are also available from the
GraphQL API