GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
59 advisories
Filter by severity
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client...
High
Unreviewed
CVE-2026-97031
was published
Oct 9, 2026
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0...
High
Unreviewed
CVE-2026-15822
was published
Oct 8, 2026
Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request...
High
Unreviewed
CVE-2026-104712
was published
Oct 5, 2026
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API.
Storing a password...
High
Unreviewed
CVE-2026-103880
was published
Oct 2, 2026
Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows...
High
Unreviewed
CVE-2026-104423
was published
Oct 2, 2026
ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows...
Moderate
Unreviewed
CVE-2026-104425
was published
Oct 2, 2026
Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers...
High
Unreviewed
CVE-2026-104431
was published
Oct 2, 2026
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by...
Moderate
Unreviewed
CVE-2026-23934
was published
Aug 18, 2026
In a query response, an attacker may send `named` multiple copies of a record that should only...
Moderate
Unreviewed
CVE-2026-75029
was published
Sep 16, 2026
Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search...
Low
Unreviewed
CVE-2026-68531
was published
Sep 15, 2026
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
High
CVE-2026-87011
was published
for
open-webui
(pip)
Sep 10, 2026
An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by...
Moderate
Unreviewed
CVE-2026-23930
was published
Aug 18, 2026
commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in...
Moderate
Unreviewed
CVE-2026-86432
was published
Sep 7, 2026
pypdf: Possible long runtimes/large memory usage when retrieving outlines
Moderate
CVE-2026-84310
was published
for
pypdf
(pip)
Sep 1, 2026
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
Moderate
CVE-2026-45822
was published
for
decode-uri-component
(npm)
Aug 31, 2026
Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes...
High
Unreviewed
CVE-2026-54874
was published
Aug 25, 2026
league/commonmark: Denial of service via deeply nested XML output
Moderate
GHSA-mj63-m3rc-8ppr
was published
for
league/commonmark
(Composer)
Aug 6, 2026
UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to...
High
Unreviewed
CVE-2026-54224
was published
Jun 18, 2026
Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of...
Moderate
Unreviewed
CVE-2026-8594
was published
May 30, 2026
Nerdbank.MessagePack has a memory amplification DoS in collection deserialization
Moderate
GHSA-qjvr-435c-5fjh
was published
for
Nerdbank.MessagePack
(NuGet)
May 29, 2026
Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY...
Moderate
Unreviewed
CVE-2026-45557
was published
May 19, 2026
Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling
Moderate
GHSA-36cp-mh65-x882
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenClaw has incomplete Fix for CVE-2026-32011: Feishu Webhook Pre-Auth Body Parsing DoS (Slow-Body / Slowloris Variant)
Moderate
CVE-2026-35665
was published
for
openclaw
(npm)
Mar 30, 2026
Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.
Moderate
Unreviewed
CVE-2025-46598
was published
Mar 20, 2026
A series of specifically crafted, unauthenticated messages can exhaust available memory and crash...
High
Unreviewed
CVE-2026-25611
was published
Feb 10, 2026
ProTip!
Advisories are also available from the
GraphQL API