GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
786 advisories
Filter by severity
Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be...
High
Unreviewed
CVE-2026-39453
was published
Oct 9, 2026
Open5GS through 2.8.0 contains a reachable assertion vulnerability in...
High
Unreviewed
CVE-2026-108105
was published
Oct 9, 2026
A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host....
Moderate
Unreviewed
CVE-2026-102916
was published
Oct 9, 2026
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core
Moderate
CVE-2026-105753
was published
for
vllm
(pip)
Oct 6, 2026
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
Moderate
CVE-2026-105754
was published
for
vllm
(pip)
Oct 5, 2026
In Modem, there is a possible system crash due to improper input validation. This could lead to...
Moderate
Unreviewed
CVE-2026-20525
was published
Oct 5, 2026
ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable...
High
Unreviewed
CVE-2026-104434
was published
Oct 2, 2026
The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node,...
Moderate
Unreviewed
CVE-2026-104428
was published
Oct 2, 2026
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in...
High
Unreviewed
CVE-2026-103104
was published
Sep 30, 2026
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation...
High
Unreviewed
CVE-2026-103108
was published
Sep 30, 2026
Pexip Infinity before 41.1 is affected by improper input validation in the media implementation...
High
Unreviewed
CVE-2026-103099
was published
Sep 30, 2026
Pexip Infinity before 40.1 is affected by improper input validation in the signaling...
High
Unreviewed
CVE-2026-103100
was published
Sep 30, 2026
Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Moderate
Unreviewed
CVE-2026-96422
was published
Sep 29, 2026
A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule...
Moderate
Unreviewed
CVE-2026-88341
was published
Sep 22, 2026
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix...
High
Unreviewed
CVE-2026-94623
was published
Sep 22, 2026
In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt()...
High
Unreviewed
CVE-2026-75894
was published
Sep 18, 2026
A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to...
Moderate
Unreviewed
CVE-2026-91147
was published
Sep 18, 2026
Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment...
Moderate
Unreviewed
CVE-2026-8674
was published
Sep 17, 2026
InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe...
High
Unreviewed
CVE-2026-92971
was published
Sep 17, 2026
A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function...
Moderate
Unreviewed
CVE-2026-92416
was published
Sep 16, 2026
If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative...
High
Unreviewed
CVE-2026-80274
was published
Sep 16, 2026
If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an...
High
Unreviewed
CVE-2026-76163
was published
Sep 16, 2026
On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3)...
High
Unreviewed
CVE-2026-73438
was published
Sep 16, 2026
FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer...
High
Unreviewed
CVE-2026-91961
was published
Sep 15, 2026
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client...
High
Unreviewed
CVE-2026-91951
was published
Sep 15, 2026
ProTip!
Advisories are also available from the
GraphQL API