GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,866
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,131 advisories
Filter by severity
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
High
CVE-2026-100368
was published
for
AlastairLundy.CliInvoke.Specializations
(NuGet)
Sep 25, 2026
CliInvoke: Argument Injection in Extensibility Runner Factory
High
CVE-2026-100369
was published
for
AlastairLundy.CliInvoke
(NuGet)
Sep 25, 2026
ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
Low
CVE-2026-56379
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
Low
GHSA-v772-658q-978p
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 23, 2026
•
withdrawn
ImageMagick has a possible heap Use After Free vulnerability in its meta coder
Low
CVE-2026-56376
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder
Moderate
GHSA-8g9f-ccmr-vfvg
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 23, 2026
•
withdrawn
ImageMagick: Memory leak in coders/txt.c without freetype
Low
CVE-2026-56371
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
Duplicate Advisory: ImageMagick: Memory leak in coders/txt.c without freetype
Low
GHSA-98gv-6gmj-cm6m
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 23, 2026
•
withdrawn
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
Moderate
CVE-2026-65829
was published
for
MPXJ.Net
(RubyGems)
Sep 22, 2026
MPXJ: XXE Vulnerability in MerlinReader
High
CVE-2026-61570
was published
for
MPXJ.Net
(RubyGems)
Sep 22, 2026
ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts
Low
CVE-2026-56370
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
Moderate
CVE-2026-81868
was published
for
Steeltoe.Security.Authorization.Certificate
(NuGet)
Sep 17, 2026
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
High
CVE-2026-81516
was published
for
Steeltoe.Discovery.Consul
(NuGet)
Sep 17, 2026
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
High
CVE-2026-81515
was published
for
Steeltoe.Discovery.Eureka
(NuGet)
Sep 17, 2026
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
Moderate
CVE-2026-75523
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Sep 17, 2026
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
High
CVE-2026-85756
was published
for
SSH.NET
(NuGet)
Sep 17, 2026
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
High
CVE-2026-69197
was published
for
Umbraco.Cms
(NuGet)
Sep 17, 2026
Marten's LINQ provider has SQL injection via unescaped string literals
Critical
CVE-2026-75513
was published
for
Marten
(NuGet)
Sep 17, 2026
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
High
CVE-2026-81192
was published
for
OpenTelemetry.Resources.Host
(NuGet)
Sep 16, 2026
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
Moderate
CVE-2026-69304
was published
for
Microsoft.AspNetCore.Server.IISIntegration
(NuGet)
Sep 9, 2026
Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2026-69522
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 9, 2026
Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
High
CVE-2026-69439
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 9, 2026
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
High
GHSA-mqvm-gmc4-6rv2
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 8, 2026
•
withdrawn
Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2026-71328
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 9, 2026
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
High
GHSA-4qhr-qf46-fcrx
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 8, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API