GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,494
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
97 advisories
Filter by severity
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
Low
CVE-2026-54522
was published
for
msgpack
(RubyGems)
Jul 30, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
GHSA-pmwx-rm49-xv39
was published
for
activerecord-tenanted
(RubyGems)
Jul 29, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
CVE-2026-54620
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
CVE-2026-54619
was published
for
sqlite3
(RubyGems)
Jul 28, 2026
Ruby json: JSON generator heap buffer overflow when streaming to an IO
Low
CVE-2026-54696
was published
for
json
(RubyGems)
Jul 23, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Low
GHSA-5qhf-9phg-95m2
was published
for
loofah
(RubyGems)
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Low
GHSA-8whx-365g-h9vv
was published
for
loofah
(RubyGems)
Jul 21, 2026
fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`
Low
CVE-2026-44162
was published
for
fluent-plugin-s3
(RubyGems)
Jun 26, 2026
Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
Low
CVE-2026-54906
was published
for
concurrent-ruby
(RubyGems)
Jun 19, 2026
Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
Low
CVE-2026-54905
was published
for
concurrent-ruby
(RubyGems)
Jun 19, 2026
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
Low
GHSA-phwj-rprq-35pp
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: Possible Use-After-Free in XInclude Processing
Low
GHSA-wfpw-mmfh-qq69
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
Low
GHSA-p67v-3w7g-wjg7
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
Low
GHSA-wjv4-x9w8-wm3h
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
Low
GHSA-9cv2-cfxc-v4v2
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
Low
GHSA-8678-w3jw-xfc2
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
Low
GHSA-5v8h-3h3q-446p
was published
for
nokogiri
(RubyGems)
Jun 19, 2026
Net::IMAP: Denial of Service via incomplete raw argument validation
Low
CVE-2026-47241
was published
for
net-imap
(RubyGems)
Jun 9, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
Low
CVE-2026-33637
was published
for
faraday
(RubyGems)
May 18, 2026
net-imap has quadratic complexity when reading response literals
Low
CVE-2026-42245
was published
for
net-imap
(RubyGems)
May 4, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
GHSA-9pm8-vwc5-w2hm
was published
for
fat_free_crm
(RubyGems)
Apr 14, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
GHSA-53p3-c7vp-4mcc
was published
for
action_text-trix
(RubyGems)
Mar 29, 2026
Loofah has improper detection of disallowed URIs via `allowed_uri?`
Low
GHSA-2j22-pr5w-6gq8
was published
for
loofah
(RubyGems)
Mar 26, 2026
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Low
CVE-2026-33658
was published
for
activestorage
(RubyGems)
Mar 25, 2026
Rails has a possible XSS vulnerability in its Action View tag helpers
Low
CVE-2026-33168
was published
for
actionview
(RubyGems)
Mar 23, 2026
ProTip!
Advisories are also available from the
GraphQL API