GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
58 advisories
Filter by severity
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Moderate
GHSA-r292-9mhp-454m
was published
for
tar
(npm)
Jul 24, 2026
node-tar: Process crash via PAX numeric path type confusion
Moderate
CVE-2026-59871
was published
for
tar
(npm)
Jul 20, 2026
node-tar: Decompression/parse DoS via unlimited input
Critical
CVE-2026-59873
was published
for
tar
(npm)
Jul 20, 2026
node-tar: Negative tar entry size causes infinite loop in archive replace
High
CVE-2026-59874
was published
for
tar
(npm)
Jul 20, 2026
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
Moderate
CVE-2026-59875
was published
for
tar
(npm)
Jul 20, 2026
Incus has arbitrary file read+write on host via templates/ symlink in malicious image
Critical
CVE-2026-48752
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Jun 26, 2026
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
Critical
CVE-2026-55447
was published
for
langflow
(pip)
Jun 19, 2026
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
High
CVE-2026-53853
was published
for
openclaw
(npm)
Jun 18, 2026
tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load
Moderate
CVE-2026-55093
was published
for
tract-nnef
(Rust)
Jun 18, 2026
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
Moderate
CVE-2026-53655
was published
for
tar
(npm)
Jun 15, 2026
Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
High
GHSA-gv7w-rqvm-qjhr
was published
for
esbuild
(npm)
Jun 12, 2026
•
withdrawn
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
Low
CVE-2026-44489
was published
for
axios
(npm)
May 29, 2026
Flowise has an MCP Security Bypass that Enables RCE
High
GHSA-m99r-2hxc-cp3q
was published
for
flowise
(npm)
May 14, 2026
Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
Critical
CVE-2026-45321
was published
for
@tanstack/arktype-adapter
(npm)
May 12, 2026
Budibase vulnerable to SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)
High
CVE-2026-45061
was published
for
budibase
(npm)
May 11, 2026
PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`
High
CVE-2026-44340
was published
for
PraisonAI
(pip)
May 11, 2026
Incus Vulnerable to Panic via Snapshot Bounds Check
High
CVE-2026-40251
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
May 4, 2026
Incus has a Nil-Pointer Dereference via Custom Volume Import
High
CVE-2026-40197
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
May 4, 2026
Incus has a Nil-Pointer Dereference Panic via Bucket Metadata
High
CVE-2026-40195
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
May 4, 2026
Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing
High
CVE-2026-40931
was published
for
compressing
(npm)
Apr 17, 2026
Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix
High
CVE-2026-35582
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 13, 2026
Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write
High
CVE-2026-35214
was published
for
@budibase/server
(npm)
Apr 4, 2026
ONNX: External Data Symlink Traversal
Moderate
CVE-2026-34447
was published
for
onnx
(pip)
Apr 1, 2026
Telnyx has malicious code in PyPI versions 4.87.1 and 4.87.2
Critical
GHSA-955r-262c-33jc
was published
for
telnyx
(pip)
Mar 30, 2026
Incus vulnerable to denial of source through crafted bucket backup file
Moderate
CVE-2026-33743
was published
for
github.com/lxc/incus
(Go)
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API