GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
74
GitHub Actions
54
Go
4,134
Maven
5,000+
npm
5,000+
NuGet
1,013
pip
5,000+
Pub
13
RubyGems
1,095
Rust
1,419
Swift
61
Unreviewed advisories
All unreviewed
5,000+
32,405 advisories
Filter by severity
golang.org/x/crypto/ssh: Invoking VerifiedPublicKeyCallback permissions skip enforcement
Critical
CVE-2026-46595
was published
for
golang.org/x/crypto/ssh
(Go)
Jun 25, 2026
golang.org/x/crypto/ssh/knownhosts vulnerable to auth bypass via unenforced @revoked status
Critical
CVE-2026-42508
was published
for
golang.org/x/crypto/ssh/knownhosts
(Go)
Jun 25, 2026
golang.org/x/crypto/ssh vulnerable to infinite loop on large channel writes
Critical
CVE-2026-39834
was published
for
golang.org/x/crypto/ssh
(Go)
Jun 25, 2026
golang.org/x/crypto/ssh: FIDO/U2F security key physical presence check can be bypassed
Critical
CVE-2026-39831
was published
for
golang.org/x/crypto/ssh
(Go)
Jun 25, 2026
golang.org/x/crypto/ssh: Invoking pathological RSA/DSA parameters may cause DoS
High
CVE-2026-39829
was published
for
golang.org/x/crypto/ssh
(Go)
Jun 25, 2026
golang.org/x/crypto/ssh: Invoking client can cause server deadlock on unexpected responses
Critical
CVE-2026-39830
was published
for
golang.org/x/crypto/ssh
(Go)
Jun 25, 2026
golang.org/x/crypto/ssh: Invoking memory leak when rejecting channels can lead to DoS
Moderate
CVE-2026-39827
was published
for
golang.org/x/crypto/ssh
(Go)
Jun 25, 2026
golang.org/x/crypto/ssh is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
Moderate
CVE-2026-39835
was published
for
golang.org/x/crypto/ssh
(Go)
Jun 25, 2026
golang.org/x/crypto/ssh vulnerable to invoking bypass of certificate restrictions
Moderate
CVE-2026-39828
was published
for
golang.org/x/crypto/ssh
(Go)
Jun 25, 2026
golang.org/x/crypto/ssh: Invoking byte arithmetic causes underflow and panic
High
CVE-2026-46597
was published
for
golang.org/x/crypto/ssh
(Go)
Jun 25, 2026
golang.org/x/crypto/ssh/agent doesn't drop invoking agent constraints when forwarding keys
Critical
CVE-2026-39832
was published
for
golang.org/x/crypto/ssh/agent
(Go)
Jun 25, 2026
golang.org/x/crypto/ssh/agent doesn't enforce invoking key constraints
Critical
CVE-2026-39833
was published
for
golang.org/x/crypto/ssh/agent
(Go)
Jun 25, 2026
golang.org/x/crypto/ssh/agent: Invoking pathological inputs can lead to client panic
Moderate
CVE-2026-46598
was published
for
golang.org/x/crypto/ssh/agent
(Go)
Jun 25, 2026
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise
Critical
CVE-2026-55166
was published
for
lemur
(pip)
Jun 25, 2026
Lemur: JWT verifier honors attacker-supplied alg, enabling ATO
Moderate
CVE-2026-55165
was published
for
lemur
(pip)
Jun 25, 2026
Lemur user-update path stores plaintext passwords
Moderate
CVE-2026-55164
was published
for
lemur
(pip)
Jun 25, 2026
Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id>
Moderate
CVE-2026-55163
was published
for
lemur
(pip)
Jun 25, 2026
Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF
Moderate
CVE-2026-55162
was published
for
lemur
(pip)
Jun 25, 2026
ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop
High
CVE-2026-53461
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition
High
CVE-2026-53460
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick: Policy Bypass can read disallowed files via symlink
Moderate
CVE-2026-49219
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions
High
CVE-2026-49218
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems
Moderate
CVE-2026-48994
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick Vulnerable to Stack Overflow in its MVG Decoder
Moderate
CVE-2026-48734
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ImageMagick has an Infinite Loop in subimage-search with crafted image
Moderate
CVE-2026-48733
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
ProTip!
Advisories are also available from the
GraphQL API