GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
36 advisories
Filter by severity
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
High
CVE-2026-56170
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Jul 21, 2026
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
High
CVE-2026-50651
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
High
CVE-2026-50525
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
High
CVE-2026-50648
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
High
CVE-2026-47302
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50273
was published
for
Datadog.Trace
(NuGet)
Jul 15, 2026
Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx
Moderate
GHSA-q6rr-fm2g-g5x8
was published
for
Scriban
(NuGet)
Jun 26, 2026
ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition
High
CVE-2026-53460
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
Moderate
CVE-2026-48515
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
Moderate
CVE-2026-48514
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
Moderate
CVE-2026-48510
was published
for
MessagePack
(NuGet)
Jun 25, 2026
NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation
Moderate
CVE-2026-55254
was published
for
NCalc.Core
(NuGet)
Jun 18, 2026
Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString
High
GHSA-24c8-4792-22hx
was published
for
Scriban.Signed
(NuGet)
May 19, 2026
ImageMagick: Policy Bypass in PSD decoder
Moderate
CVE-2026-45031
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
OneCollector exporter reads unbounded HTTP response bodies
Moderate
CVE-2026-41484
was published
for
OpenTelemetry.Exporter.OneCollector
(NuGet)
Apr 29, 2026
OpenTelemetry.Resources.Azure has an unbounded HTTP response body read
Moderate
CVE-2026-41483
was published
for
OpenTelemetry.Resources.Azure
(NuGet)
Apr 29, 2026
OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure
Moderate
CVE-2026-41310
was published
for
OpenTelemetry.Exporter.Zipkin
(NuGet)
Apr 28, 2026
OpenTelemetry.Sampler.AWS & OpenTelemetry.Resources.AWS have unbounded HTTP response body reads
Moderate
CVE-2026-41173
was published
for
OpenTelemetry.Resources.AWS
(NuGet)
Apr 23, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
Moderate
CVE-2026-41078
was published
for
OpenTelemetry.Exporter.Jaeger
(NuGet)
Apr 18, 2026
Meridian: Multiple defense-in-depth gaps (collection/depth caps, telemetry, retry, fan-out)
High
GHSA-f5v8-v6q3-q4h6
was published
for
Meridian.Mapping
(NuGet)
Apr 16, 2026
Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString
Moderate
GHSA-m2p3-hwv5-xpqw
was published
for
Scriban
(NuGet)
Mar 24, 2026
Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service
High
GHSA-v66j-x4hw-fv9g
was published
for
Scriban
(NuGet)
Mar 24, 2026
Scriban Affected by Memory Exhaustion (OOM) via Unbounded String Generation (Denial of Service)
Moderate
GHSA-5rpf-x9jg-8j5p
was published
for
Scriban.Signed
(NuGet)
Mar 19, 2026
.NET Denial of Service Vulnerability
High
CVE-2026-26130
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2026
ProTip!
Advisories are also available from the
GraphQL API