GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
145 advisories
Filter by severity
ImageMagick has an integer overflow in despeckle operation causing a heap buffer overflow on 32-bit builds
Moderate
CVE-2026-34238
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 13, 2026
ImageMagick has a heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit builds
Moderate
CVE-2026-33900
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 13, 2026
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT vulnerable to Integer Overflow or Wraparound
Moderate
CVE-2026-40046
was published
for
org.apache.activemq:activemq-all
(Maven)
Apr 9, 2026
OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write
High
CVE-2026-34589
was published
for
OpenEXR
(pip)
Apr 8, 2026
OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
High
CVE-2026-34588
was published
for
OpenEXR
(pip)
Apr 8, 2026
OpenEXR: integer overflow to OOB write in uncompress_b44_impl()
High
CVE-2026-34544
was published
for
openexr
(pip)
Apr 3, 2026
libp2p-gossipsub: Remote crash via unchecked Instant overflow in heartbeat backoff expiry handling
High
CVE-2026-34219
was published
for
libp2p-gossipsub
(Rust)
Mar 30, 2026
NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead
High
CVE-2026-27889
was published
for
github.com/nats-io/nats-server
(Go)
Mar 25, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Moderate
CVE-2026-33306
was published
for
bcrypt
(RubyGems)
Mar 19, 2026
Gossipsub PRUNE.backoff Duration Overflow
High
CVE-2026-33040
was published
for
libp2p-gossipsub
(Rust)
Mar 18, 2026
UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
High
CVE-2026-32875
was published
for
ujson
(pip)
Mar 18, 2026
File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely
Moderate
CVE-2026-32759
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 16, 2026
Yamux vulnerable to remote Panic via malformed WindowUpdate credit
High
CVE-2026-31814
was published
for
yamux
(Rust)
Mar 13, 2026
ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder
Moderate
CVE-2026-28493
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick Has Signed Integer Overflow in SIXEL Decoder, Leading to Memory Corruption
Moderate
CVE-2026-25970
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
neqo-qpack has iInteger overflow in qpack dynamic table indexing
Moderate
GHSA-6w86-wgwq-rgq8
was published
for
neqo-qpack
(Rust)
Mar 4, 2026
Apache ActiveMQ is Vulnerable to Integer Overflow or Wraparound
Moderate
CVE-2025-66168
was published
for
org.apache.activemq:activemq-all
(Maven)
Mar 4, 2026
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
ImageMagick: Integer Overflow in PSB (PSD v2) RLE decoding path causes heap Out of Bounds reads for 32-bit builds
Low
CVE-2026-25984
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: Integer overflow or wraparound and incorrect conversion between numeric types in the internal SVG decoder
High
CVE-2026-25989
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick has heap-buffer-overflow via signed integer overflow in WriteUHDRImage when writing UHDR images with large dimensions
High
CVE-2026-25794
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
Bug fixes in hpke-rs, hpke-rs-rust-crypto
High
GHSA-g433-pq76-6cmf
was published
for
hpke-rs
(Rust)
Feb 13, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
Moderate
CVE-2026-24889
was published
for
soroban-sdk
(Rust)
Jan 28, 2026
Quick-Media Batik Codec FIX Package has Buffer Overflow Vulnerability in PNG Codec
Moderate
CVE-2026-24807
was published
for
com.github.liuyueyi.media:batik-codec-fix
(Maven)
Jan 27, 2026
ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
Moderate
CVE-2026-23833
was published
for
esphome
(pip)
Jan 21, 2026
ProTip!
Advisories are also available from the
GraphQL API