GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
4,171 advisories
Filter by severity
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
High
CVE-2026-33625
was published
for
lmdeploy
(pip)
Sep 18, 2026
ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails...
Moderate
Unreviewed
CVE-2026-93590
was published
Sep 18, 2026
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per...
Moderate
Unreviewed
CVE-2026-93587
was published
Sep 18, 2026
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied...
Moderate
Unreviewed
CVE-2026-88798
was published
Sep 18, 2026
A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of...
Moderate
Unreviewed
CVE-2026-93310
was published
Sep 18, 2026
A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some...
Low
Unreviewed
CVE-2026-93309
was published
Sep 18, 2026
A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an...
Low
Unreviewed
CVE-2026-93308
was published
Sep 18, 2026
A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of...
Low
Unreviewed
CVE-2026-93307
was published
Sep 18, 2026
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
Moderate
CVE-2026-86000
was published
for
soupsieve
(pip)
Sep 17, 2026
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
Moderate
CVE-2026-85999
was published
for
soupsieve
(pip)
Sep 17, 2026
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
High
CVE-2026-81876
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.r5
(Maven)
Sep 17, 2026
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
High
CVE-2026-81875
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.r5
(Maven)
Sep 17, 2026
Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)
High
CVE-2026-68537
was published
for
fulgur
(Rust)
Sep 17, 2026
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
High
CVE-2026-68523
was published
for
fulgur
(Rust)
Sep 17, 2026
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
High
CVE-2026-85721
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Moderate
CVE-2026-69147
was published
for
vllm
(pip)
Sep 17, 2026
vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on...
High
Unreviewed
CVE-2026-92942
was published
Sep 17, 2026
A security flaw has been discovered in vgmstream up to r2117. This issue affects the function...
Moderate
Unreviewed
CVE-2026-92879
was published
Sep 17, 2026
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser...
High
Unreviewed
CVE-2026-92596
was published
Sep 17, 2026
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
High
CVE-2026-63128
was published
for
rmcp
(Rust)
Sep 16, 2026
A remote attacker could cause excessive resource consumption by supplying specially crafted...
High
Unreviewed
CVE-2026-76646
was published
Sep 16, 2026
node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion
High
CVE-2026-68904
was published
for
node-opcua
(npm)
Sep 16, 2026
A flaw was found in the theme localization endpoints of the keycloak-services component, which is...
High
Unreviewed
CVE-2026-79651
was published
Sep 16, 2026
A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file...
Moderate
Unreviewed
CVE-2026-92363
was published
Sep 16, 2026
A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the...
Moderate
Unreviewed
CVE-2026-92362
was published
Sep 16, 2026
ProTip!
Advisories are also available from the
GraphQL API