GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
5,025 advisories
Filter by severity
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
Moderate
GHSA-jpcw-4wr7-c3vq
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
Moderate
CVE-2026-59949
was published
for
at.yawk.lz4:lz4-java
(Maven)
Jul 24, 2026
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.
This...
High
Unreviewed
CVE-2026-45816
was published
Jul 24, 2026
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
Low
GHSA-qh5g-q395-cx4j
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a...
High
Unreviewed
CVE-2026-50032
was published
Jul 23, 2026
A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a...
Moderate
Unreviewed
CVE-2026-13070
was published
Jul 22, 2026
A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill...
High
Unreviewed
CVE-2026-13065
was published
Jul 22, 2026
In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set...
Moderate
Unreviewed
CVE-2026-55717
was published
Jul 22, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Low
CVE-2026-55984
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in...
Moderate
Unreviewed
CVE-2026-63762
was published
Jul 20, 2026
A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS)...
High
Unreviewed
CVE-2026-15352
was published
Jul 16, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
Moderate
CVE-2026-53719
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated,...
High
Unreviewed
CVE-2026-52865
was published
Jul 15, 2026
A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0,...
High
Unreviewed
CVE-2025-56363
was published
Jul 15, 2026
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over...
Moderate
Unreviewed
CVE-2026-56168
was published
Jul 14, 2026
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to...
Moderate
Unreviewed
CVE-2026-50366
was published
Jul 14, 2026
Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-50315
was published
Jul 14, 2026
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to...
Moderate
Unreviewed
CVE-2026-57976
was published
Jul 14, 2026
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer...
High
Unreviewed
CVE-2026-58101
was published
Jul 14, 2026
Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol...
High
Unreviewed
CVE-2026-60109
was published
Jul 9, 2026
GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified...
Moderate
Unreviewed
CVE-2026-56288
was published
Jul 9, 2026
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of...
Moderate
Unreviewed
CVE-2026-15171
was published
Jul 8, 2026
A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk...
Moderate
Unreviewed
CVE-2026-50812
was published
Jul 8, 2026
Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer dereference vulnerability in...
High
Unreviewed
CVE-2026-56401
was published
Jul 8, 2026
A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master...
Moderate
Unreviewed
CVE-2026-50810
was published
Jul 8, 2026
ProTip!
Advisories are also available from the
GraphQL API