GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
528 advisories
Filter by severity
A missing release of resources in the illumos name service cache daemon (nscd) allows a local...
Moderate
Unreviewed
CVE-2026-104112
was published
Oct 9, 2026
Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early
High
CVE-2026-107286
was published
for
pydantic-ai
(pip)
Oct 8, 2026
Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor
Moderate
CVE-2026-107834
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 8, 2026
A flaw was found in SSSD. A local user can trigger a Denial of Service (DoS) by exploiting a race...
Moderate
Unreviewed
CVE-2026-104045
was published
Oct 6, 2026
A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory...
Moderate
Unreviewed
CVE-2026-104031
was published
Oct 6, 2026
A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM) responder allows a...
Moderate
Unreviewed
CVE-2026-104035
was published
Oct 6, 2026
undici vulnerable to Denial of Service via orphaned RetryHandler response body
Moderate
CVE-2026-18149
was published
for
undici
(npm)
Sep 29, 2026
Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET...
Moderate
Unreviewed
CVE-2026-97686
was published
Sep 28, 2026
Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder....
High
Unreviewed
CVE-2026-100657
was published
Sep 26, 2026
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: ucsi: unregister...
Moderate
Unreviewed
CVE-2026-100079
was published
Sep 25, 2026
Missing release of resource after effective lifetime, Comparison using wrong factors...
Unknown
Unreviewed
CVE-2026-79677
was published
Sep 23, 2026
vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where...
Moderate
Unreviewed
CVE-2026-94625
was published
Sep 22, 2026
InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release...
High
Unreviewed
CVE-2026-92983
was published
Sep 17, 2026
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
High
CVE-2026-63128
was published
for
rmcp
(Rust)
Sep 16, 2026
A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive...
High
Unreviewed
CVE-2026-20250
was published
Sep 16, 2026
Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol ...
Moderate
Unreviewed
CVE-2026-72931
was published
Sep 8, 2026
When a container-level ErrorHandler is configured (the mitigation for finding 221000), each...
Moderate
Unreviewed
CVE-2026-59320
was published
Aug 27, 2026
Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped...
Moderate
Unreviewed
CVE-2026-59654
was published
Aug 21, 2026
Bouncy Castle: Zeroisation of sensitive key material on garbage collection relies on finalization.
High
CVE-2026-13505
was published
for
org.bouncycastle:bc-fips
(Maven)
Aug 8, 2026
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE...
High
Unreviewed
CVE-2026-20124
was published
Aug 5, 2026
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Moderate
CVE-2026-64607
was published
for
org.apache.httpcomponents.client5:httpclient5
(Maven)
Jul 31, 2026
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
Moderate
CVE-2026-73508
was published
for
io.netty:netty-codec-dns
(Maven)
Jul 24, 2026
An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process...
Moderate
Unreviewed
CVE-2026-12353
was published
Jul 23, 2026
In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve...
Moderate
Unreviewed
CVE-2026-56444
was published
Jul 22, 2026
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ)...
Low
Unreviewed
CVE-2026-41637
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API