GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,726
Maven
5,000+
npm
4,331
NuGet
763
pip
4,107
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
197 advisories
Filter by severity
ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)
Moderate
CVE-2025-62594
was published
for
Magick.NET-Q16-HDRI-OpenMP-arm64
(NuGet)
Oct 27, 2025
orx-pinned-vec has undefined behavior in index_of_ptr with empty slices
Low
GHSA-h5j3-crg5-8jqm
was published
for
orx-pinned-vec
(Rust)
Oct 21, 2025
wrflib has a soundness issue and is unmaintained
Low
GHSA-466c-pfvv-v83g
was published
for
wrflib
(Rust)
Oct 3, 2025
SPDK is vulnerable to buffer overflow in the NVMe-oF target component
Moderate
CVE-2025-57275
was published
for
spdk
(pip)
Oct 1, 2025
slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check
Moderate
CVE-2025-55159
was published
for
slab
(Rust)
Aug 11, 2025
sparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflow
Low
CVE-2025-6494
was published
for
nokogiri
(RubyGems)
Jun 23, 2025
•
withdrawn
sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow
Low
CVE-2025-6490
was published
for
nokogiri
(RubyGems)
Jun 22, 2025
•
withdrawn
wasmtime_jit_debug Dumps Undefined Memory by `JitDumpFile`
Moderate
GHSA-9ghp-w2hm-vfpf
was published
for
wasmtime-jit-debug
(Rust)
Jun 17, 2025
Arrow2 allows out of bounds access in public safe API
High
GHSA-wv8j-m3hx-924j
was published
for
arrow2
(Rust)
May 30, 2025
tanton_engine has unsound public API
Moderate
GHSA-m2xr-2vj4-wh94
was published
for
tanton_engine
(Rust)
May 6, 2025
Panic in mp3-metadata due to the lack of bounds checking
Moderate
GHSA-927q-g9w9-pm54
was published
for
mp3-metadata
(Rust)
Apr 30, 2025
jsonschema2pojo has Improper Restriction of Operations within the Bounds of a Memory Buffer
Moderate
CVE-2025-3588
was published
for
org.jsonschema2pojo:jsonschema2pojo-core
(Maven)
Apr 14, 2025
Ouch Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability
Moderate
CVE-2024-13941
was published
for
ouch
(Rust)
Apr 1, 2025
Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC
High
CVE-2024-36129
was published
for
go.opentelemetry.io/collector/config/configgrpc
(Go)
Jun 5, 2024
Duplicate Advisory: Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459
Low
GHSA-r3w4-36x6-7r99
was published
for
nokogiri
(RubyGems)
May 14, 2024
•
withdrawn
Handling untrusted input can result in a crash, leading to loss of availability / denial of service
High
CVE-2024-30253
was published
for
@solana/web3.js
(npm)
Apr 17, 2024
Eclipse Vert.x memory leak
Moderate
CVE-2024-1023
was published
for
io.vertx:vertx-core
(Maven)
Mar 27, 2024
Vyper's `_abi_decode` vulnerable to Memory Overflow
Low
CVE-2024-26149
was published
for
vyper
(pip)
Feb 26, 2024
Vyper's external calls can overflow return data to return input buffer
Low
CVE-2024-24560
was published
for
vyper
(pip)
Feb 2, 2024
Vyper's bounds check on built-in `slice()` function can be overflowed
Critical
CVE-2024-24561
was published
for
vyper
(pip)
Feb 1, 2024
Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow
Moderate
CVE-2023-27506
was published
for
intel-tensorflow
(pip)
Aug 11, 2023
MindSpore vulnerable to memory corruption
Moderate
CVE-2023-2970
was published
for
mindspore
(pip)
May 30, 2023
Snappier vulnerable to buffer overrun due to improper restriction of operations within the bounds of a memory buffer
High
CVE-2023-28638
was published
for
Snappier
(NuGet)
Mar 27, 2023
go-codec-dagpb vulnerable to panic when decoding invalid blocks
High
CVE-2022-2584
was published
for
github.com/ipld/go-codec-dagpb
(Go)
Dec 28, 2022
linux-loader reading beyond EOF could lead to infinite loop
Low
CVE-2022-23523
was published
for
linux-loader
(Rust)
Dec 12, 2022
ProTip!
Advisories are also available from the
GraphQL API