GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
310 advisories
Filter by severity
MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS
Moderate
CVE-2026-107382
was published
for
mariadb
(npm)
Oct 8, 2026
music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of GHSA-v6c2-xwv6-8xf7)
Moderate
CVE-2026-107392
was published
for
music-metadata
(npm)
Oct 8, 2026
Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks
High
CVE-2026-107214
was published
for
github.com/xuri/excelize/v2
(Go)
Oct 8, 2026
RabbitMQ: Malformed UTF-8 in shortstr properties permanently disables RPC consumers
Moderate
CVE-2026-106122
was published
for
com.rabbitmq:amqp-client
(Maven)
Oct 7, 2026
Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an...
Low
Unreviewed
CVE-2026-78243
was published
Oct 7, 2026
Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially...
Moderate
Unreviewed
CVE-2026-102413
was published
Oct 6, 2026
vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites)
Moderate
CVE-2026-105757
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service
Moderate
CVE-2026-105756
was published
for
vllm
(pip)
Oct 5, 2026
vm2: Host Promise rejection from an exposed constructor can terminate the vm2 host process
High
CVE-2026-100722
was published
for
vm2
(npm)
Oct 5, 2026
vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
Critical
CVE-2026-92954
was published
for
vm2
(npm)
Oct 5, 2026
In multiple places, there is a possible denial of service due to an uncaught exception. This...
High
Unreviewed
CVE-2026-58859
was published
Oct 5, 2026
Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift...
High
Unreviewed
CVE-2026-96277
was published
Oct 2, 2026
Uncaught exception vulnerability in Apache Thrift Perl bindings.
This issue affects Apache...
High
Unreviewed
CVE-2026-96286
was published
Oct 2, 2026
Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift...
High
Unreviewed
CVE-2026-96294
was published
Oct 2, 2026
Uncaught exception, Improper validation of specified quantity in input, Improperly controlled...
High
Unreviewed
CVE-2026-94646
was published
Oct 2, 2026
Uncaught exception, improper handling of exceptional conditions, improper resource shutdown...
High
Unreviewed
CVE-2026-90440
was published
Oct 2, 2026
Uncaught exception vulnerability in Apache Thrift PHP bindings.
This issue affects Apache...
High
Unreviewed
CVE-2026-94642
was published
Oct 2, 2026
Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings.
This issue...
High
Unreviewed
CVE-2026-85493
was published
Oct 2, 2026
improper handling of exceptional conditions, Allocation of resources without limits or throttling...
High
Unreviewed
CVE-2026-94639
was published
Oct 2, 2026
devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
High
GHSA-x5rw-q4pp-hg5g
was published
for
devalue
(npm)
Oct 1, 2026
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
Moderate
CVE-2026-92081
was published
for
fastify
(npm)
Sep 30, 2026
Astro: Malformed port in the Host header can crash the Node adapter
High
CVE-2026-102984
was published
for
@astrojs/node
(npm)
Sep 30, 2026
A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI...
Low
Unreviewed
CVE-2026-103387
was published
Sep 30, 2026
PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)
Moderate
CVE-2026-101918
was published
for
PyJWT
(pip)
Sep 30, 2026
Nest: Remote process termination via a deeply nested microservice message pattern
High
CVE-2026-102281
was published
for
@nestjs/microservices
(npm)
Sep 29, 2026
ProTip!
Advisories are also available from the
GraphQL API