GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,406
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,124
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
542 advisories
Filter by severity
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
High
CVE-2026-56170
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Jul 21, 2026
Microsoft Security Advisory CVE-2026-50526 – .NET Tampering Vulnerability
High
CVE-2026-50526
was published
for
Microsoft.NET.Build.Containers
(NuGet)
Jul 21, 2026
Microsoft Security Advisory CVE-2026-47300 – .NET Elevation of Privilege Vulnerability
High
CVE-2026-47300
was published
for
Microsoft.AspNetCore.Authentication.Negotiate
(NuGet)
Jul 21, 2026
Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability
High
CVE-2026-47303
was published
for
Microsoft.AspNetCore.Authentication.Negotiate
(NuGet)
Jul 21, 2026
Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability
High
CVE-2026-50527
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 21, 2026
Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege Vulnerability
High
CVE-2026-50650
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Jul 21, 2026
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
High
CVE-2026-50651
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
High
CVE-2026-50525
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
High
CVE-2026-50528
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
High
CVE-2026-50648
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
High
CVE-2026-50524
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
High
CVE-2026-47304
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
High
CVE-2026-47302
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
High
CVE-2026-57108
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Prompty: Arbitrary file read via file reference expansion
High
CVE-2026-53598
was published
for
@prompty/core
(npm)
Jul 17, 2026
dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50273
was published
for
Datadog.Trace
(NuGet)
Jul 15, 2026
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
High
GHSA-7jvp-hj45-2f2m
was published
for
Scriban
(NuGet)
Jul 6, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
High
CVE-2026-50200
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Jul 2, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
High
CVE-2026-50196
was published
for
Steeltoe.Discovery.Eureka
(NuGet)
Jul 2, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
High
CVE-2026-50194
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Jul 2, 2026
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
High
CVE-2026-49451
was published
for
Microsoft.OpenAPI
(NuGet)
Jun 30, 2026
ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop
High
CVE-2026-53461
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition
High
CVE-2026-53460
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions
High
CVE-2026-49218
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
High
CVE-2026-48506
was published
for
MessagePack
(NuGet)
Jun 25, 2026
ProTip!
Advisories are also available from the
GraphQL API