GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,722
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,568
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,816 advisories
Filter by severity
Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized...
High
Unreviewed
CVE-2026-70065
was published
Sep 8, 2026
Missing release of memory after effective lifetime in Active Directory Domain Services allows an...
High
Unreviewed
CVE-2026-69809
was published
Sep 8, 2026
Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized...
Moderate
Unreviewed
CVE-2026-69781
was published
Sep 8, 2026
Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized...
High
Unreviewed
CVE-2026-69588
was published
Sep 8, 2026
Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized...
Moderate
Unreviewed
CVE-2026-69497
was published
Sep 8, 2026
Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized...
Moderate
Unreviewed
CVE-2026-69405
was published
Sep 8, 2026
Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that...
High
Unreviewed
CVE-2026-16028
was published
Sep 7, 2026
rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or...
Moderate
Unreviewed
CVE-2026-18313
was published
Sep 5, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of...
Moderate
Unreviewed
CVE-2026-18076
was published
Sep 4, 2026
Missing release of memory after effective lifetime vulnerability in Softing smartLink allows...
Moderate
Unreviewed
CVE-2026-13148
was published
Sep 4, 2026
A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco...
High
Unreviewed
CVE-2026-20281
was published
Sep 2, 2026
ImageMagick: Memory Leak when providing invalid options to the cli
Low
GHSA-cvhv-g4rq-3hmw
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Sep 2, 2026
Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive...
Moderate
Unreviewed
CVE-2026-38819
was published
Aug 28, 2026
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame.
Spring...
High
Unreviewed
CVE-2026-47888
was published
Aug 27, 2026
Duplicate Advisory: Nokogiri XSLT transform has a memory leak
Moderate
GHSA-rh9x-7xjc-vwx2
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via...
Moderate
Unreviewed
CVE-2026-59295
was published
Aug 24, 2026
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on...
High
Unreviewed
CVE-2026-76235
was published
Aug 19, 2026
An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the...
High
Unreviewed
CVE-2026-71675
was published
Aug 18, 2026
A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64...
Low
Unreviewed
CVE-2026-19382
was published
Aug 10, 2026
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
Moderate
CVE-2026-56818
was published
for
io.netty:netty-codec-redis
(Maven)
Aug 7, 2026
Issue summary: A malicious TLS server can cause a memory leak in a TLS
client that has enabled...
High
Unreviewed
CVE-2026-54876
was published
Aug 5, 2026
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code...
High
Unreviewed
CVE-2026-51400
was published
Aug 4, 2026
In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release...
High
Unreviewed
CVE-2026-63252
was published
Aug 4, 2026
A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2...
High
Unreviewed
CVE-2026-12932
was published
Jul 30, 2026
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
Moderate
CVE-2026-67430
was published
for
mcp
(RubyGems)
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API