GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,651
Maven
5,000+
npm
4,279
NuGet
760
pip
4,066
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
Applications using affected versions of Ehcache 3.x can experience degraded cache-write...
Low
Unreviewed
CVE-2025-2529
was published
Oct 15, 2025
CometBFT's invalid BitArray handling can lead to network halt
High
GHSA-hrhf-2vcr-ghch
was published
for
github.com/cometbft/cometbft
(Go)
Oct 14, 2025
libsql-sqlite3-parser crash due to invalid UTF-8 input
Low
CVE-2025-47736
was published
for
libsql-sqlite3-parser
(Rust)
May 9, 2025
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7...
Moderate
Unreviewed
CVE-2024-55594
was published
Mar 14, 2025
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4...
Moderate
Unreviewed
CVE-2023-42784
was published
Mar 11, 2025
CVE-2025-0343: Swift ASN.1 can crash when parsing maliciously formed BER/DER
Low
CVE-2025-0343
was published
for
github.com/apple/swift-asn1
(Swift)
Jan 14, 2025
MongoDB Rust driver may issue unintended commands
Moderate
CVE-2024-6382
was published
for
mongodb
(Rust)
Jul 2, 2024
An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6...
Moderate
Unreviewed
CVE-2024-22815
was published
Apr 22, 2024
Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows...
Moderate
Unreviewed
CVE-2024-22809
was published
Apr 22, 2024
An Improper Handling of Syntactically Invalid Structure vulnerability in Object Flooding...
High
Unreviewed
CVE-2024-21612
was published
Jan 12, 2024
NLnet Labs’ Routinator up to and including version 0.12.1 may crash when trying to parse certain...
High
Unreviewed
CVE-2023-39915
was published
Sep 13, 2023
BER/CER/DER decoder panics on invalid input
High
CVE-2023-39914
was published
for
bcder
(Rust)
Sep 13, 2023
Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow...
Critical
Unreviewed
CVE-2021-38443
was published
May 6, 2022
Authentication Bypass in dex
Critical
CVE-2020-27847
was published
for
github.com/dexidp/dex
(Go)
Dec 20, 2021
ProTip!
Advisories are also available from the
GraphQL API