GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,090 advisories
Filter by severity
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
High
CVE-2026-50525
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
High
CVE-2026-50528
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
High
CVE-2026-50648
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
High
CVE-2026-50524
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
High
CVE-2026-47304
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
High
CVE-2026-47302
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
High
CVE-2026-57108
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass
Moderate
CVE-2026-54570
was published
for
AngleSharp
(NuGet)
Jul 17, 2026
Prompty: Arbitrary file read via file reference expansion
High
CVE-2026-53598
was published
for
@prompty/core
(npm)
Jul 17, 2026
dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50273
was published
for
Datadog.Trace
(NuGet)
Jul 15, 2026
Umbraco.AI discloses sensitive application configuration values
Moderate
GHSA-q3v2-xj35-9grx
was published
for
Umbraco.AI
(NuGet)
Jul 14, 2026
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
High
GHSA-7jvp-hj45-2f2m
was published
for
Scriban
(NuGet)
Jul 6, 2026
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
Low
CVE-2026-50268
was published
for
Steeltoe.Configuration.Encryption
(NuGet)
Jul 2, 2026
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
Moderate
CVE-2026-50267
was published
for
Steeltoe.Configuration.Abstractions
(NuGet)
Jul 2, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
Moderate
CVE-2026-50202
was published
for
Steeltoe.Security.Authentication.CloudFoundryBase
(NuGet)
Jul 2, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
Moderate
CVE-2026-50201
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Jul 2, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
High
CVE-2026-50200
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Jul 2, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
High
CVE-2026-50196
was published
for
Steeltoe.Discovery.Eureka
(NuGet)
Jul 2, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
High
CVE-2026-50194
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Jul 2, 2026
CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder
Moderate
CVE-2026-48796
was published
for
CefSharp.Common
(NuGet)
Jun 30, 2026
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
High
CVE-2026-49451
was published
for
Microsoft.OpenAPI
(NuGet)
Jun 30, 2026
ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image
Moderate
CVE-2026-53465
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 26, 2026
ImageMagick: Memory Leak in wand option parser when providing invalid arguments
Moderate
CVE-2026-53464
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 26, 2026
Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)
Moderate
GHSA-6q7j-xr26-3h2c
was published
for
Scriban
(NuGet)
Jun 26, 2026
Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx
Moderate
GHSA-q6rr-fm2g-g5x8
was published
for
Scriban
(NuGet)
Jun 26, 2026
ProTip!
Advisories are also available from the
GraphQL API