Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,025 advisories

Loading
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema Moderate
GHSA-jpcw-4wr7-c3vq was published for github.com/getkin/kin-openapi (Go) Jul 24, 2026
matiasinsaurralde Credited to matiasinsaurralde
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges Moderate
CVE-2026-59949 was published for at.yawk.lz4:lz4-java (Maven) Jul 24, 2026
sectroyer Credited to sectroyer
ImageMagick: Heap-use-after-free via XMP profile could result in a crash Low
GHSA-qh5g-q395-cx4j was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service Low
CVE-2026-55984 was published for code.gitea.io/gitea (Go) Jul 21, 2026
martijnperdaan52 Credited to martijnperdaan52
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization Moderate
CVE-2026-53719 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
ProTip! Advisories are also available from the GraphQL API