GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,752
Maven
5,000+
npm
4,357
NuGet
765
pip
4,121
Pub
12
RubyGems
961
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
15 advisories
Filter by severity
Array size is not checked in sized-chunks
High
CVE-2020-25793
was published
for
sized-chunks
(Rust)
Aug 25, 2021
Array size is not checked in sized-chunks
High
CVE-2020-25791
was published
for
sized-chunks
(Rust)
Aug 25, 2021
Unaligned references in sized-chunks
High
CVE-2020-25796
was published
for
sized-chunks
(Rust)
Aug 25, 2021
Array size is not checked in sized-chunks
High
CVE-2020-25792
was published
for
sized-chunks
(Rust)
Aug 25, 2021
Improper Input Validation in GoGo Protobuf
High
CVE-2021-3121
was published
for
github.com/gogo/protobuf
(Go)
Mar 28, 2022
golang.org/x/net/html Improper Validation of Array Index vulnerability
High
CVE-2018-17848
was published
for
golang.org/x/net
(Go)
May 13, 2022
Go Ethereum LES protocol implementation vulnerable to Denial of Service
High
CVE-2018-12018
was published
for
github.com/ethereum/go-ethereum
(Go)
May 14, 2022
`libsqlite3-sys` via C SQLite improperly validates array index
High
CVE-2022-35737
was published
for
libsqlite3-sys
(Rust)
Aug 4, 2022
Improper Validation of Array Index in GJSON
High
CVE-2020-36067
was published
for
github.com/tidwall/gjson
(Go)
Feb 6, 2023
ADMesh improper array index validation
High
CVE-2022-38072
was published
for
admesh
(pip)
Apr 3, 2023
audify vulnerable to Improper Validation of Array Index
High
CVE-2024-21522
was published
for
audify
(npm)
Jul 10, 2024
CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data
High
GHSA-p7mv-53f2-4cwj
was published
for
github.com/cometbft/cometbft
(Go)
Nov 6, 2024
Ollama Server Vulnerable to Denial of Service (DoS) Attack
High
CVE-2025-1975
was published
for
github.com/ollama/ollama
(Go)
May 16, 2025
Fiber panics when fiber.Ctx.BodyParser parses invalid range index
High
CVE-2025-48075
was published
for
github.com/gofiber/fiber/v2
(Go)
May 22, 2025
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
High
CVE-2025-62372
was published
for
vllm
(pip)
Nov 20, 2025
ProTip!
Advisories are also available from the
GraphQL API