GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
33,466 advisories
Filter by severity
Guzzle: URI fragments disclosed in redirect Referer headers
Moderate
GHSA-h95v-h523-3mw8
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Guzzle: Host-only cookie scope is not preserved
Moderate
GHSA-wm3w-8rrp-j577
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Guzzle: Unbounded response cookies risk denial of service
Moderate
GHSA-f283-ghqc-fg79
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
Moderate
GHSA-8mv7-9c27-98vc
was published
for
astro
(npm)
Jul 20, 2026
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
Low
GHSA-hp3v-mfqw-h74c
was published
for
@astrojs/netlify
(npm)
Jul 20, 2026
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
Low
CVE-2026-12590
was published
for
body-parser
(npm)
Jul 20, 2026
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
Low
CVE-2026-59730
was published
for
@astrojs/node
(npm)
Jul 20, 2026
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Moderate
CVE-2026-59729
was published
for
astro
(npm)
Jul 20, 2026
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
Moderate
CVE-2026-59728
was published
for
@astrojs/rss
(npm)
Jul 20, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Low
CVE-2026-59727
was published
for
astro
(npm)
Jul 20, 2026
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
High
CVE-2026-59205
was published
for
pillow
(pip)
Jul 20, 2026
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
High
CVE-2026-59204
was published
for
pillow
(pip)
Jul 20, 2026
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
Moderate
CVE-2026-59203
was published
for
pillow
(pip)
Jul 20, 2026
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
High
CVE-2026-59200
was published
for
Pillow
(pip)
Jul 20, 2026
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
High
CVE-2026-59199
was published
for
Pillow
(pip)
Jul 20, 2026
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
Moderate
CVE-2026-59198
was published
for
Pillow
(pip)
Jul 20, 2026
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
High
CVE-2026-59197
was published
for
Pillow
(pip)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
High
CVE-2026-50651
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
Moderate
CVE-2026-50659
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
High
CVE-2026-50525
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
High
CVE-2026-50528
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
High
CVE-2026-50648
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
High
CVE-2026-50524
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
High
CVE-2026-47304
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
High
CVE-2026-47302
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API