GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,967
Maven
5,000+
npm
5,000+
NuGet
973
pip
5,000+
Pub
13
RubyGems
1,064
Rust
1,387
Swift
56
Unreviewed advisories
All unreviewed
5,000+
150 advisories
Filter by severity
Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability...
High
Unreviewed
CVE-2026-49127
was published
May 28, 2026
A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check....
Moderate
Unreviewed
CVE-2026-42015
was published
May 27, 2026
ImageMagick: Heap Buffer Over-Write in json and yaml encoder of a single byte due to incorrect fix
Moderate
GHSA-jqq5-8px3-9m6m
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 21, 2026
An off-by-two error in lp_write() in papd in Netatalk 2.0.0 through 4.4.2 allows an adjacent...
Moderate
Unreviewed
CVE-2026-44065
was published
May 21, 2026
ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.
Moderate
CVE-2026-46559
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
ImageMagick: Out-of-Bounds Read of a single byte in meta encoder
Moderate
CVE-2026-45358
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE...
Low
Unreviewed
CVE-2026-44603
was published
May 7, 2026
Velocidex Velociraptor has an off-by-one error
Moderate
CVE-2026-7572
was published
for
www.velocidex.com/golang/velociraptor
(Go)
May 6, 2026
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over...
Low
Unreviewed
CVE-2026-43964
was published
May 4, 2026
mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
Low
Unreviewed
CVE-2026-43860
was published
May 4, 2026
Netfoil has incorrect allowlist enforcement
Moderate
GHSA-84g5-x8j3-7235
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Apr 29, 2026
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs...
Moderate
Unreviewed
CVE-2026-6861
was published
Apr 22, 2026
ImageMagick has has an off-by-one origin validation in allows out-of-bounds read in morphology processing
Low
GHSA-q8h3-jv9v-57qx
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
ImageMagick has an off-by-one error in MSL decoder could result in crash
Moderate
CVE-2026-40312
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
Moby has an Off-by-one error in its plugin privilege validation
Moderate
CVE-2026-33997
was published
for
github.com/docker/docker
(Go)
Mar 27, 2026
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an...
Moderate
Unreviewed
CVE-2026-4887
was published
Mar 26, 2026
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling,...
Moderate
Unreviewed
CVE-2026-34085
was published
Mar 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: liquidio: Fix off-by...
Moderate
Unreviewed
CVE-2026-23257
was published
Mar 18, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: liquidio: Fix off-by...
Moderate
Unreviewed
CVE-2026-23256
was published
Mar 18, 2026
arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the...
High
Unreviewed
CVE-2026-28520
was published
Mar 16, 2026
yauzl contains an off-by-one error
Moderate
CVE-2026-31988
was published
for
yauzl
(npm)
Mar 12, 2026
Envoy affected by off-by-one write in JsonEscaper::escapeString()
Moderate
CVE-2026-26309
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 10, 2026
OpenClaw has allowlist exec-guard bypass via env -S
Moderate
CVE-2026-31992
was published
for
openclaw
(npm)
Mar 3, 2026
ml-dsa's UseHint function has off by two error when r0 equals zero
Moderate
GHSA-h37v-hp6w-2pp8
was published
for
ml-dsa
(Rust)
Feb 2, 2026
In the Linux kernel, the following vulnerability has been resolved:
dm-verity: disable recursive...
Moderate
Unreviewed
CVE-2025-71161
was published
Jan 23, 2026
ProTip!
Advisories are also available from the
GraphQL API