GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
852 advisories
Filter by severity
HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows...
High
Unreviewed
CVE-2026-97362
was published
Sep 24, 2026
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via...
High
Unreviewed
CVE-2026-87082
was published
Sep 22, 2026
Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD...
High
Unreviewed
CVE-2026-82560
was published
Sep 19, 2026
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function...
High
Unreviewed
CVE-2026-93690
was published
Sep 18, 2026
react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU
High
CVE-2026-84997
was published
for
react/http
(Composer)
Sep 17, 2026
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
High
CVE-2026-81876
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.r5
(Maven)
Sep 17, 2026
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
High
CVE-2026-68523
was published
for
fulgur
(Rust)
Sep 17, 2026
ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion
High
CVE-2026-85715
was published
for
exifreader
(npm)
Sep 17, 2026
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
Moderate
CVE-2026-62949
was published
for
asyncssh
(pip)
Sep 17, 2026
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure...
High
Unreviewed
CVE-2026-20154
was published
Sep 16, 2026
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect...
High
Unreviewed
CVE-2026-91952
was published
Sep 15, 2026
Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for...
Moderate
Unreviewed
CVE-2026-77117
was published
Sep 15, 2026
Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for...
Moderate
Unreviewed
CVE-2026-80489
was published
Sep 15, 2026
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem...
Low
Unreviewed
CVE-2023-37366
was published
Sep 14, 2026
strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate...
High
Unreviewed
CVE-2026-78132
was published
Sep 11, 2026
strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
Moderate
Unreviewed
CVE-2026-78129
was published
Sep 11, 2026
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
Moderate
CVE-2026-87013
was published
for
open-webui
(pip)
Sep 10, 2026
zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in...
Moderate
Unreviewed
CVE-2026-89045
was published
Sep 10, 2026
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
Moderate
CVE-2026-88000
was published
for
open-webui
(pip)
Sep 9, 2026
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
Moderate
CVE-2026-88002
was published
for
open-webui
(pip)
Sep 9, 2026
smol-toml: Denial of Service via malformed TOML documents
High
CVE-2026-85730
was published
for
smol-toml
(npm)
Sep 9, 2026
libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to...
Moderate
Unreviewed
CVE-2026-6554
was published
Sep 5, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM...
Moderate
Unreviewed
CVE-2026-78543
was published
Sep 4, 2026
LiquidJS has an infinite loop vulnerability in its `strip_html` filter
High
CVE-2026-61556
was published
for
liquidjs
(npm)
Sep 3, 2026
pypdf: Possible infinite loop for TreeObject.insert_child
Moderate
CVE-2026-84309
was published
for
pypdf
(pip)
Sep 1, 2026
ProTip!
Advisories are also available from the
GraphQL API