GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,900
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,373
Swift
54
Unreviewed advisories
All unreviewed
5,000+
12,220 advisories
Filter by severity
A malicious actor with access to the network could exploit an Improper Input Validation...
Critical
Unreviewed
CVE-2026-34910
was published
May 22, 2026
A malicious actor with access to the network and high privileges could exploit an Improper Input...
Critical
Unreviewed
CVE-2026-33000
was published
May 22, 2026
js-libp2p: Memory DoS via subscription flood of unique topics
High
CVE-2026-46679
was published
for
@libp2p/gossipsub
(npm)
May 21, 2026
Improper input validation, Unrestricted upload of file with dangerous type vulnerability in...
High
Unreviewed
CVE-2026-9157
was published
May 21, 2026
Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179...
Moderate
Unreviewed
CVE-2026-9124
was published
May 20, 2026
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform...
Moderate
Unreviewed
CVE-2026-20240
was published
May 20, 2026
Multiple flaws have been identified in `named` related to the handling of DNS messages whose...
High
Unreviewed
CVE-2026-5946
was published
May 20, 2026
@libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes
High
CVE-2026-45783
was published
for
@libp2p/kad-dht
(npm)
May 19, 2026
Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
Moderate
CVE-2026-46341
was published
for
@apify/actors-mcp-server
(npm)
May 19, 2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This...
Critical
Unreviewed
CVE-2026-8959
was published
May 19, 2026
Algernon: handler.lua discovery walks parent directories above the server root
Critical
CVE-2026-45721
was published
for
github.com/xyproto/algernon
(Go)
May 19, 2026
Improper Input Validation vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before...
Moderate
Unreviewed
CVE-2026-31378
was published
May 19, 2026
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
Low
Unreviewed
CVE-2026-28751
was published
May 19, 2026
OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
High
CVE-2026-45685
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability
High
CVE-2026-35433
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
May 18, 2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
High
Unreviewed
CVE-2026-45495
was published
May 18, 2026
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-45492
was published
May 18, 2026
An attacker in a privileged network position may be able to leak sensitive information. A path...
Moderate
Unreviewed
CVE-2026-20685
was published
May 18, 2026
OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads
High
CVE-2026-45678
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent
Moderate
CVE-2026-45676
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
eduMFA: Unauthenticated Failcounter Increment on Resolver Tokens via /validate/check
Moderate
GHSA-74r7-3mjm-jc5v
was published
for
edumfa
(pip)
May 18, 2026
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
High
CVE-2026-45135
was published
for
github.com/caddyserver/caddy/v2
(Go)
May 18, 2026
Beetl's SpELFunction extension function has an expression injection risk
Moderate
CVE-2026-8759
was published
for
com.ibeetl:beetl-spring-classic
(Maven)
May 17, 2026
A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function...
Moderate
Unreviewed
CVE-2026-8751
was published
May 17, 2026
A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils...
Low
Unreviewed
CVE-2026-8735
was published
May 17, 2026
ProTip!
Advisories are also available from the
GraphQL API