GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,535
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,515
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
128 advisories
Filter by severity
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
High
GHSA-pfvm-w89x-94jw
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
High
CVE-2026-13697
was published
for
undici
(npm)
Aug 3, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
High
GHSA-hrxh-6v49-42gf
was published
for
google.golang.org/grpc
(Go)
Jul 21, 2026
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
High
CVE-2026-59892
was published
for
@opentelemetry/propagator-jaeger
(npm)
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
CVE-2026-61666
was published
for
websocket-driver
(RubyGems)
Jul 21, 2026
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a...
High
Unreviewed
CVE-2026-64612
was published
Jul 20, 2026
SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler...
High
Unreviewed
CVE-2026-63747
was published
Jul 20, 2026
SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module...
High
Unreviewed
CVE-2025-71391
was published
Jul 18, 2026
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...
High
Unreviewed
CVE-2024-58368
was published
Jul 18, 2026
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and...
High
Unreviewed
CVE-2024-58369
was published
Jul 18, 2026
SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span...
High
Unreviewed
CVE-2024-58364
was published
Jul 18, 2026
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting...
High
Unreviewed
CVE-2024-58359
was published
Jul 18, 2026
SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time()...
High
Unreviewed
CVE-2024-58357
was published
Jul 18, 2026
SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the...
High
Unreviewed
CVE-2024-58361
was published
Jul 18, 2026
SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor...
High
Unreviewed
CVE-2024-58365
was published
Jul 18, 2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an...
High
Unreviewed
CVE-2026-47480
was published
Jul 14, 2026
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
High
CVE-2026-53530
was published
for
ratex-parser
(Rust)
Jul 7, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
High
GHSA-wjjj-24cx-f28g
was published
for
surrealdb
(Rust)
Jul 1, 2026
@grpc/grpc-js: A malformed request can cause a server crash
High
CVE-2026-48068
was published
for
@grpc/grpc-js
(npm)
Jun 11, 2026
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
High
CVE-2026-48069
was published
for
@grpc/grpc-js
(npm)
Jun 11, 2026
An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that...
High
Unreviewed
CVE-2026-9509
was published
May 29, 2026
nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item
High
CVE-2026-46545
was published
for
nimiq-primitives
(Rust)
May 21, 2026
OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
High
CVE-2026-45685
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
multiparty: Denial of Service via Prototype Pollution leads to Uncaught Exception
High
CVE-2026-8161
was published
for
multiparty
(npm)
May 18, 2026
ProTip!
Advisories are also available from the
GraphQL API