GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,090 advisories
Filter by severity
ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments
Moderate
CVE-2026-53463
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 26, 2026
ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails
Moderate
CVE-2026-53462
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 26, 2026
ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop
High
CVE-2026-53461
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition
High
CVE-2026-53460
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick: Policy Bypass can read disallowed files via symlink
Moderate
CVE-2026-49219
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions
High
CVE-2026-49218
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems
Moderate
CVE-2026-48994
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick Vulnerable to Stack Overflow in its MVG Decoder
Moderate
CVE-2026-48734
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick has an Infinite Loop in subimage-search with crafted image
Moderate
CVE-2026-48733
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method
Moderate
CVE-2026-48724
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
Moderate
CVE-2026-48517
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
Moderate
CVE-2026-48516
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
Moderate
CVE-2026-48515
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
Moderate
CVE-2026-48514
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement
Moderate
CVE-2026-48513
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
Moderate
CVE-2026-48512
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
Moderate
CVE-2026-48511
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
Moderate
CVE-2026-48510
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
Moderate
CVE-2026-48509
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
High
CVE-2026-48506
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
High
CVE-2026-48502
was published
for
MessagePack
(NuGet)
Jun 25, 2026
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
High
CVE-2026-54784
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
High
CVE-2026-54783
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
Critical
CVE-2026-54782
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
High
CVE-2026-54781
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API