GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
43 advisories
Filter by severity
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an...
High
Unreviewed
CVE-2026-73446
was published
Sep 16, 2026
Partition interceptor may be improperly added while sending message.
Spring Cloud Stream 5.0.0 -...
Low
Unreviewed
CVE-2026-59305
was published
Aug 27, 2026
Russh: Channel-scoped server callbacks can be reached without an open channel
Moderate
CVE-2026-68930
was published
for
russh
(Rust)
Aug 3, 2026
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated...
Critical
Unreviewed
CVE-2026-44108
was published
Jul 30, 2026
cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in...
Moderate
Unreviewed
CVE-2026-67217
was published
Jul 29, 2026
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block...
Moderate
Unreviewed
CVE-2026-65100
was published
Jul 29, 2026
Due to incorrect behavior order a low privileged remote attacker could trigger account...
High
Unreviewed
CVE-2026-14169
was published
Jul 28, 2026
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
Low
Unreviewed
CVE-2026-56355
was published
Jun 20, 2026
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
Moderate
CVE-2026-44919
was published
for
ironic
(pip)
May 14, 2026
GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
High
CVE-2026-45033
was published
for
@github/copilot
(npm)
May 11, 2026
Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of...
Low
Unreviewed
CVE-2026-44600
was published
May 7, 2026
kanidmd_lib: Image upload validators run before authorization; PNG validator panics on malformed input
Moderate
GHSA-84jc-3hj2-hwc7
was published
for
kanidmd_lib
(Rust)
May 6, 2026
OpenStack Horizon has Incorrect Behavior Order
Moderate
CVE-2026-43002
was published
for
horizon
(pip)
May 5, 2026
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the...
Moderate
Unreviewed
CVE-2026-41254
was published
Apr 18, 2026
In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes...
Moderate
Unreviewed
CVE-2026-40223
was published
Apr 10, 2026
Duplicate Advisory: OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcement
Moderate
GHSA-2j53-2c28-g9v2
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete
Moderate
GHSA-p6j4-wvmc-vx2h
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation
Moderate
GHSA-8f9r-gr6r-x63q
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenClaw versions 2026.3.11 through 2026.3.24 contain a session isolation bypass vulnerability...
High
Unreviewed
CVE-2026-35636
was published
Apr 10, 2026
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within...
Low
Unreviewed
CVE-2026-35386
was published
Apr 2, 2026
OpenClaw: Mattermost callback dispatch allowed non-allowlisted sender actions
Moderate
CVE-2026-35652
was published
for
openclaw
(npm)
Mar 26, 2026
Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver /...
Moderate
Unreviewed
CVE-2025-9904
was published
Sep 29, 2025
The improper order of AUTHORIZED_CTM_IP validation in the Control-M/Agent, where the Control-M...
Moderate
Unreviewed
CVE-2025-55114
was published
Sep 16, 2025
Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can...
Moderate
Unreviewed
CVE-2025-48965
was published
Jul 20, 2025
In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass...
Moderate
Unreviewed
CVE-2021-47688
was published
Jun 23, 2025
ProTip!
Advisories are also available from the
GraphQL API