GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,513
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
25 advisories
Filter by severity
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
High
CVE-2026-73564
was published
for
github.com/fatedier/frp
(Go)
Jul 24, 2026
golang.org/x/crypto vulnerable to infinite loop on large channel writes
Critical
CVE-2026-39834
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function
High
CVE-2026-37462
was published
for
github.com/osrg/gobgp/v4
(Go)
Jun 3, 2026
OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI
High
CVE-2026-45686
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
iskorotkov/avro: Integer Overflow in Decoder
High
CVE-2026-46384
was published
for
github.com/iskorotkov/avro/v2
(Go)
May 18, 2026
bettercap Has an Integer Coercion Error in the ippReadChunkedBody Function
Low
CVE-2026-8275
was published
for
github.com/bettercap/bettercap/v2
(Go)
May 11, 2026
MediaMTX affected by CVE-2026-27143 due to vulnerable dependency
Low
GHSA-2ccx-cjjh-r2j8
was published
for
github.com/bluenviron/mediamtx
(Go)
May 6, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
High
CVE-2026-41602
was published
for
github.com/apache/thrift
(Go)
Apr 28, 2026
go-ntlmssp NTLM challenges can panic on malformed payloads
Moderate
CVE-2026-32952
was published
for
github.com/Azure/go-ntlmssp
(Go)
Apr 23, 2026
NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead
High
CVE-2026-27889
was published
for
github.com/nats-io/nats-server
(Go)
Mar 25, 2026
File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely
Moderate
CVE-2026-32759
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 16, 2026
go-f3 module vulnerable to integer overflow leading to panic
High
CVE-2025-59942
was published
for
github.com/filecoin-project/go-f3
(Go)
Sep 29, 2025
Cosmos SDK's Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt
High
GHSA-p22h-3m2v-cmgh
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Jul 8, 2025
Babylon Integer Overflow in Distribution Module CumulativeRewardRatio Calculation Leading to Chain Halt
High
GHSA-869w-47c6-fq8q
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
Nethermind Juno Potential Denial of Service (DoS) via Integer Overflow
High
CVE-2025-29072
was published
for
github.com/NethermindEth/juno
(Go)
Mar 27, 2025
containerd has an integer overflow in User ID handling
Moderate
CVE-2024-40635
was published
for
github.com/containerd/containerd
(Go)
Mar 17, 2025
ASA-2024-010: cosmossdk.io/math: Mismatched bit-length validation in sdk.Int and sdk.Dec can lead to panic
High
GHSA-7225-m954-23v7
was published
for
cosmossdk.io/math
(Go)
Nov 20, 2024
pgproto3 SQL Injection via Protocol Message Size Overflow
High
GHSA-7jwh-3vrq-q3m8
was published
for
github.com/jackc/pgproto3
(Go)
Mar 4, 2024
pgx SQL Injection via Protocol Message Size Overflow
High
CVE-2024-27304
was published
for
github.com/jackc/pgx
(Go)
Mar 4, 2024
Integer overflow in chunking helper causes dispatching to miss elements or panic
High
CVE-2024-27101
was published
for
github.com/authzed/spicedb
(Go)
Mar 1, 2024
Denial of Service in Bytom
High
CVE-2018-18206
was published
for
github.com/bytom/bytom
(Go)
Feb 15, 2022
Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC
Moderate
CVE-2021-43784
was published
for
github.com/opencontainers/runc
(Go)
Dec 7, 2021
Integer Overflow in go-jose
High
CVE-2016-9123
was published
for
github.com/square/go-jose
(Go)
Jun 23, 2021
Integer overflow in github.com/gorilla/websocket
High
CVE-2020-27813
was published
for
github.com/gorilla/websocket
(Go)
May 18, 2021
Integer Overflow or Wraparound in NATS Server
High
CVE-2019-13126
was published
for
github.com/nats-io/nats-server/v2
(Go)
May 18, 2021
ProTip!
Advisories are also available from the
GraphQL API