GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,595
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,823
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
314 advisories
Filter by severity
ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width
Moderate
GHSA-rrjr-v56m-ww88
was published
for
ParquetSharp
(NuGet)
Apr 24, 2026
OpenTelemetry.Sampler.AWS & OpenTelemetry.Resources.AWS have unbounded HTTP response body reads
Moderate
CVE-2026-41173
was published
for
OpenTelemetry.Resources.AWS
(NuGet)
Apr 23, 2026
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
Moderate
CVE-2026-40894
was published
for
OpenTelemetry.Api
(NuGet)
Apr 23, 2026
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
Moderate
CVE-2026-40891
was published
for
OpenTelemetry.Exporter.OpenTelemetryProtocol
(NuGet)
Apr 23, 2026
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
Moderate
CVE-2026-40182
was published
for
OpenTelemetry.Exporter.OpenTelemetryProtocol
(NuGet)
Apr 23, 2026
OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle
Moderate
CVE-2026-41511
was published
for
OpenMcdf
(NuGet)
Apr 22, 2026
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
Moderate
GHSA-9j88-vvj5-vhgr
was published
for
MailKit
(NuGet)
Apr 18, 2026
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
Moderate
CVE-2026-41078
was published
for
OpenTelemetry.Exporter.Jaeger
(NuGet)
Apr 18, 2026
ImageMagick has has a stack-buffer-overflow in MNG encoder with oversized pallete
Moderate
GHSA-98cp-rj9f-6v5g
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
ImageMagick has a heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit builds
Moderate
CVE-2026-33900
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 13, 2026
ImageMagick has a heap-Buffer-Overflow write of a single zero byte when parsing xml.
Moderate
CVE-2026-33899
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 13, 2026
DNN: Force Friend Request Acceptance
Moderate
CVE-2026-40305
was published
for
DotNetNuke.Core
(NuGet)
Apr 10, 2026
ImageMagick has an off-by-one error in MSL decoder could result in crash
Moderate
CVE-2026-40312
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
ImageMagick has a heap-use-after-free via XMP profile could result in a crash when printing the values.
Moderate
CVE-2026-40311
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
ImageMagick has a heap out-of-bounds write in JP2 encoder
Moderate
CVE-2026-40310
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float
Moderate
CVE-2026-40183
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.
Moderate
CVE-2026-40169
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
ImageMagick has an out-of-bounds read in sample operation
Moderate
CVE-2026-33905
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
ImageMagick has a Stack Overflow via Recursive FX Expression Parsing
Moderate
CVE-2026-33902
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
Moderate
CVE-2026-40021
was published
for
log4net
(NuGet)
Apr 10, 2026
ImageMagick has an integer overflow in despeckle operation causing a heap buffer overflow on 32-bit builds
Moderate
CVE-2026-34238
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 13, 2026
Potential XSS vulnerability in jQuery
Moderate
CVE-2020-11022
was published
for
athlon1600/youtube-downloader
(RubyGems)
Apr 29, 2020
ImageMagick has an Out-of-bounds Write via InterpretImageFilename
Moderate
CVE-2026-33536
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 26, 2026
ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
Moderate
CVE-2026-33535
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 26, 2026
Scriban has Multiple Denial-of-Service Vectors via Unbounded Resource Consumption During Expression Evaluation
Moderate
GHSA-xw6w-9jjh-p9cr
was published
for
Scriban
(NuGet)
Mar 24, 2026
ProTip!
Advisories are also available from the
GraphQL API