GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,771
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
1,124 advisories
Filter by severity
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
Moderate
CVE-2026-81868
was published
for
Steeltoe.Security.Authorization.Certificate
(NuGet)
Sep 17, 2026
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
High
CVE-2026-81516
was published
for
Steeltoe.Discovery.Consul
(NuGet)
Sep 17, 2026
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
High
CVE-2026-81515
was published
for
Steeltoe.Discovery.Eureka
(NuGet)
Sep 17, 2026
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
Moderate
CVE-2026-75523
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Sep 17, 2026
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
High
CVE-2026-85756
was published
for
SSH.NET
(NuGet)
Sep 17, 2026
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
High
CVE-2026-69197
was published
for
Umbraco.Cms
(NuGet)
Sep 17, 2026
Marten's LINQ provider has SQL injection via unescaped string literals
Critical
CVE-2026-75513
was published
for
Marten
(NuGet)
Sep 17, 2026
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
High
CVE-2026-81192
was published
for
OpenTelemetry.Resources.Host
(NuGet)
Sep 16, 2026
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
Moderate
CVE-2026-69304
was published
for
Microsoft.AspNetCore.Server.IISIntegration
(NuGet)
Sep 9, 2026
Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2026-69522
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 9, 2026
Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
High
CVE-2026-69439
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 9, 2026
Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2026-71328
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 9, 2026
Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability
High
CVE-2026-50646
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Sep 8, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
CVE-2026-62815
was published
for
Microsoft.Native.Quic.MsQuic.OpenSSL
(NuGet)
Sep 8, 2026
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability
Moderate
CVE-2026-62900
was published
for
Microsoft.Build.Tasks.Git
(NuGet)
Sep 8, 2026
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
High
GHSA-4qhr-qf46-fcrx
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 8, 2026
•
withdrawn
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
High
GHSA-q72m-f2r4-w4cw
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 8, 2026
•
withdrawn
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
High
GHSA-mqvm-gmc4-6rv2
was published
for
Microsoft.DiaSymReader.Native
(NuGet)
Sep 8, 2026
•
withdrawn
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
Moderate
GHSA-v3f6-m9j2-437p
was published
for
Microsoft.AspNetCore.Server.IISIntegration
(NuGet)
Sep 8, 2026
•
withdrawn
ImageMagick: Memory Leak when providing invalid options to the cli
Low
GHSA-cvhv-g4rq-3hmw
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Sep 2, 2026
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
High
GHSA-pfvm-w89x-94jw
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
High
GHSA-jwjp-4649-v8jp
was published
for
SIPSorcery
(NuGet)
Aug 12, 2026
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
High
CVE-2026-48798
was published
for
SSH.NET
(NuGet)
Aug 12, 2026
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Moderate
CVE-2026-62902
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Aug 11, 2026
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
High
CVE-2026-62871
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Aug 11, 2026
ProTip!
Advisories are also available from the
GraphQL API