GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
2,353 advisories
Filter by severity
Contao: The registration module re-sends activation mails
Moderate
CVE-2026-107843
was published
for
contao/core-bundle
(Composer)
Oct 9, 2026
Vikunja: Planka migration retains an unbounded aggregate of attacker-served attachments and can OOM the API
High
CVE-2026-91970
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Denial of service via decompression bomb in the data import
High
CVE-2026-91979
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
An unauthenticated user with network access to the Ops Manager web port can repeatedly request...
Moderate
Unreviewed
CVE-2026-87110
was published
Oct 9, 2026
OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission...
Low
Unreviewed
CVE-2026-107885
was published
Oct 9, 2026
When parsing a Range header containing a large number of small ranges, FileServer(FS),...
High
Unreviewed
CVE-2026-78667
was published
Oct 9, 2026
Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory...
High
Unreviewed
CVE-2026-94440
was published
Oct 9, 2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0...
Moderate
Unreviewed
CVE-2026-78399
was published
Oct 8, 2026
enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash
Moderate
CVE-2026-107379
was published
for
enshrined/svg-sanitize
(Composer)
Oct 8, 2026
amqp091-go: Pre-negotiation frame limit is not enforced to 4KB
Moderate
CVE-2026-107386
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Oct 8, 2026
Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl
Moderate
CVE-2026-107294
was published
for
pydantic-ai
(pip)
Oct 8, 2026
Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows iterator loop for days
High
CVE-2026-107212
was published
for
github.com/xuri/excelize/v2
(Go)
Oct 8, 2026
Uncontrolled eviction in the browser session table of the REST API in Progressive Robot...
Moderate
Unreviewed
CVE-2026-107586
was published
Oct 8, 2026
Uncontrolled eviction in the pending sign-in tables of the REST API in Progressive Robot...
Moderate
Unreviewed
CVE-2026-107585
was published
Oct 8, 2026
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0...
High
Unreviewed
CVE-2026-16176
was published
Oct 8, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.8.9, 18...
Moderate
Unreviewed
CVE-2026-1403
was published
Oct 7, 2026
yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs
Moderate
CVE-2026-106450
was published
for
at.yawk.lz4:lz4-java
(Maven)
Oct 7, 2026
A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to...
Moderate
Unreviewed
CVE-2026-20173
was published
Oct 7, 2026
A flaw was found in `sssd-kcm`. A local user or process able to connect to the `sssd-kcm` UNIX...
Moderate
Unreviewed
CVE-2026-80048
was published
Oct 7, 2026
A flaw was found in SSSD (System Security Services Daemon). When Identity Provider (IdP)...
Moderate
Unreviewed
CVE-2026-104046
was published
Oct 6, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to...
Moderate
Unreviewed
CVE-2026-102411
was published
Oct 6, 2026
Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding
High
CVE-2026-41510
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 6, 2026
Allocation of resources without limits or throttling vulnerability in ESET PROTECT On-Prem...
Moderate
Unreviewed
CVE-2025-8352
was published
Oct 6, 2026
Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)
Moderate
CVE-2026-105747
was published
for
docling
(pip)
Oct 6, 2026
Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions.
Moderate
Unreviewed
CVE-2026-39767
was published
Oct 6, 2026
ProTip!
Advisories are also available from the
GraphQL API