GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,060 advisories
Filter by severity
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no...
Unknown
Unreviewed
CVE-2026-73635
was published
Aug 15, 2026
s2n-quic has excessive memory allocation
Moderate
CVE-2026-10740
was published
for
s2n-quic
(Rust)
Aug 14, 2026
Grav: Unauthenticated denial of service via unbounded image derivative dimensions
High
CVE-2026-53653
was published
for
getgrav/grav
(Composer)
Aug 14, 2026
FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS...
High
Unreviewed
CVE-2026-72838
was published
Aug 14, 2026
A flaw was found in libdm. A remote attacker could craft a malicious Logical Volume Manager (LVM)...
Moderate
Unreviewed
CVE-2026-19617
was published
Aug 14, 2026
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead...
High
Unreviewed
CVE-2026-56859
was published
Aug 14, 2026
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of...
High
Unreviewed
CVE-2026-56862
was published
Aug 14, 2026
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new...
High
Unreviewed
CVE-2026-56853
was published
Aug 14, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to...
Moderate
Unreviewed
CVE-2026-17076
was published
Aug 13, 2026
A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a...
Moderate
Unreviewed
CVE-2026-72684
was published
Aug 13, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of...
Moderate
Unreviewed
CVE-2026-72674
was published
Aug 13, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of...
Moderate
Unreviewed
CVE-2026-72667
was published
Aug 13, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of...
Moderate
Unreviewed
CVE-2026-72659
was published
Aug 13, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of...
Moderate
Unreviewed
CVE-2026-72653
was published
Aug 13, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of...
Moderate
Unreviewed
CVE-2026-72651
was published
Aug 13, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of...
Moderate
Unreviewed
CVE-2026-49089
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to...
High
Unreviewed
CVE-2026-17199
was published
Aug 13, 2026
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes
valid QUIC Initial...
High
Unreviewed
CVE-2026-14456
was published
Aug 13, 2026
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending...
High
Unreviewed
CVE-2026-71469
was published
Aug 13, 2026
IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local...
Low
Unreviewed
CVE-2026-18096
was published
Aug 12, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19...
Moderate
Unreviewed
CVE-2026-7427
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to...
High
Unreviewed
CVE-2026-17271
was published
Aug 12, 2026
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0...
Moderate
Unreviewed
CVE-2026-71408
was published
Aug 12, 2026
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication...
High
Unreviewed
CVE-2025-41770
was published
Aug 12, 2026
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized...
High
Unreviewed
CVE-2026-54113
was published
Aug 11, 2026
ProTip!
Advisories are also available from the
GraphQL API