GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
232 advisories
Filter by severity
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
High
GHSA-hrxh-6v49-42gf
was published
for
google.golang.org/grpc
(Go)
Jul 21, 2026
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
High
CVE-2026-59892
was published
for
@opentelemetry/propagator-jaeger
(npm)
Jul 21, 2026
websocket-driver-ruby: Denial of service via malformed Host header
High
CVE-2026-61666
was published
for
websocket-driver
(RubyGems)
Jul 21, 2026
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
Moderate
CVE-2026-14631
was published
for
webpack-dev-server
(npm)
Jul 20, 2026
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
Moderate
CVE-2026-59875
was published
for
tar
(npm)
Jul 20, 2026
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a...
High
Unreviewed
CVE-2026-64612
was published
Jul 20, 2026
SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler...
High
Unreviewed
CVE-2026-63747
was published
Jul 20, 2026
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...
High
Unreviewed
CVE-2024-58368
was published
Jul 18, 2026
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and...
High
Unreviewed
CVE-2024-58369
was published
Jul 18, 2026
SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module...
High
Unreviewed
CVE-2025-71391
was published
Jul 18, 2026
SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor...
High
Unreviewed
CVE-2024-58365
was published
Jul 18, 2026
SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span...
High
Unreviewed
CVE-2024-58364
was published
Jul 18, 2026
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting...
High
Unreviewed
CVE-2024-58359
was published
Jul 18, 2026
SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time()...
High
Unreviewed
CVE-2024-58357
was published
Jul 18, 2026
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that...
Moderate
Unreviewed
CVE-2024-58358
was published
Jul 18, 2026
SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the...
High
Unreviewed
CVE-2024-58361
was published
Jul 18, 2026
ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes
Moderate
CVE-2026-53496
was published
for
exifreader
(npm)
Jul 17, 2026
nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys
Low
CVE-2026-54541
was published
for
nimiq-primitives
(Rust)
Jul 16, 2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an...
High
Unreviewed
CVE-2026-47480
was published
Jul 14, 2026
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
High
CVE-2026-53530
was published
for
ratex-parser
(Rust)
Jul 7, 2026
Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface...
Low
Unreviewed
CVE-2026-27844
was published
Jul 7, 2026
Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator...
Low
Unreviewed
CVE-2026-27790
was published
Jul 7, 2026
Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection
Moderate
CVE-2026-52739
was published
for
zebra-state
(Rust)
Jul 2, 2026
Zebra: Finalized address balance credit-first overflow on consensus-valid blocks
Moderate
CVE-2026-52738
was published
for
zebra-state
(Rust)
Jul 2, 2026
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers
Moderate
GHSA-c8w6-x74f-vmg3
was published
for
zebra-rpc
(Rust)
Jul 2, 2026
ProTip!
Advisories are also available from the
GraphQL API