GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,849
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,131 advisories
Filter by severity
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
High
CVE-2026-100368
was published
for
AlastairLundy.CliInvoke.Specializations
(NuGet)
Sep 25, 2026
CliInvoke: Argument Injection in Extensibility Runner Factory
High
CVE-2026-100369
was published
for
AlastairLundy.CliInvoke
(NuGet)
Sep 25, 2026
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
Moderate
CVE-2026-65829
was published
for
MPXJ.Net
(RubyGems)
Sep 22, 2026
MPXJ: XXE Vulnerability in MerlinReader
High
CVE-2026-61570
was published
for
MPXJ.Net
(RubyGems)
Sep 22, 2026
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
Moderate
CVE-2026-81868
was published
for
Steeltoe.Security.Authorization.Certificate
(NuGet)
Sep 17, 2026
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
High
CVE-2026-81516
was published
for
Steeltoe.Discovery.Consul
(NuGet)
Sep 17, 2026
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
High
CVE-2026-81515
was published
for
Steeltoe.Discovery.Eureka
(NuGet)
Sep 17, 2026
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
Moderate
CVE-2026-75523
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Sep 17, 2026
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
High
CVE-2026-85756
was published
for
SSH.NET
(NuGet)
Sep 17, 2026
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
High
CVE-2026-69197
was published
for
Umbraco.Cms
(NuGet)
Sep 17, 2026
Marten's LINQ provider has SQL injection via unescaped string literals
Critical
CVE-2026-75513
was published
for
Marten
(NuGet)
Sep 17, 2026
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
High
CVE-2026-81192
was published
for
OpenTelemetry.Resources.Host
(NuGet)
Sep 16, 2026
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
Moderate
CVE-2026-69304
was published
for
Microsoft.AspNetCore.Server.IISIntegration
(NuGet)
Sep 9, 2026
Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2026-69522
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 9, 2026
Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
High
CVE-2026-69439
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 9, 2026
Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2026-71328
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 9, 2026
Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability
High
CVE-2026-50646
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Sep 8, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
CVE-2026-62815
was published
for
Microsoft.Native.Quic.MsQuic.OpenSSL
(NuGet)
Sep 8, 2026
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability
Moderate
CVE-2026-62900
was published
for
Microsoft.Build.Tasks.Git
(NuGet)
Sep 8, 2026
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
High
GHSA-4qhr-qf46-fcrx
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 8, 2026
•
withdrawn
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
High
GHSA-q72m-f2r4-w4cw
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 8, 2026
•
withdrawn
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
High
GHSA-mqvm-gmc4-6rv2
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 8, 2026
•
withdrawn
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
Moderate
GHSA-v3f6-m9j2-437p
was published
for
Microsoft.AspNetCore.Server.IISIntegration
(NuGet)
Sep 8, 2026
•
withdrawn
ImageMagick: Memory Leak when providing invalid options to the cli
Low
GHSA-cvhv-g4rq-3hmw
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Sep 2, 2026
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
High
GHSA-pfvm-w89x-94jw
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
ProTip!
Advisories are also available from the
GraphQL API