GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,662
Maven
5,000+
npm
4,289
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
35 advisories
Filter by severity
ImageMagick has Integer Overflow in BMP Decoder (ReadBMP)
Moderate
CVE-2025-62171
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Oct 28, 2025
russh is missing overflow checks during channel windows adjust
Moderate
CVE-2025-54804
was published
for
russh
(Rust)
Aug 4, 2025
Duplicate Advisory: transpose: Buffer overflow due to integer overflow
Moderate
GHSA-p444-p2rm-hvrw
was published
for
transpose
(Rust)
Jul 27, 2025
•
withdrawn
Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits
Moderate
CVE-2025-52520
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
Jul 10, 2025
containerd has an integer overflow in User ID handling
Moderate
CVE-2024-40635
was published
for
github.com/containerd/containerd
(Go)
Mar 17, 2025
BoringSSLAEADContext in Netty Repeats Nonces
Moderate
CVE-2024-36121
was published
for
io.netty.incubator:netty-incubator-codec-ohttp
(Maven)
Jun 5, 2024
libdav1d-sys affected by dav1d AV1 decoder integer overflow
Moderate
GHSA-mc39-h54g-pvw6
was published
for
libdav1d-sys
(Rust)
Apr 5, 2024
transpose: Buffer overflow due to integer overflow
Moderate
CVE-2023-53156
was published
for
transpose
(Rust)
Apr 5, 2024
Vapor contains an integer overflow in URI leading to potential host spoofing
Moderate
CVE-2024-21631
was published
for
github.com/vapor/vapor
(Swift)
Jan 3, 2024
.eth registrar controller can shorten the duration of registered names
Moderate
CVE-2023-38698
was published
for
@ensdomains/ens-contracts
(npm)
Aug 1, 2023
snappy-java's Integer Overflow vulnerability in compress leads to DoS
Moderate
CVE-2023-34454
was published
for
org.xerial.snappy:snappy-java
(Maven)
Jun 15, 2023
snappy-java's Integer Overflow vulnerability in shuffle leads to DoS
Moderate
CVE-2023-34453
was published
for
org.xerial.snappy:snappy-java
(Maven)
Jun 15, 2023
TensorFlow vulnerable to segfault when opening multiframe gif
Moderate
CVE-2023-25667
was published
for
tensorflow
(pip)
Mar 24, 2023
TensorFlow vulnerable to Int overflow in `RaggedRangeOp`
Moderate
CVE-2022-35940
was published
for
tensorflow
(pip)
Sep 16, 2022
Incorrect parsing of EVM reversion exit reason in RPC
Moderate
CVE-2022-36008
was published
for
fc-rpc
(Rust)
Aug 18, 2022
`CHECK` failure in depthwise ops via overflows
Moderate
GHSA-mw6j-hh29-h379
was published
for
tensorflow
(pip)
May 25, 2022
Integer overflow in `SpaceToBatchND`
Moderate
CVE-2022-29203
was published
for
tensorflow
(pip)
May 24, 2022
Integer overflow in BCrypt class in Spring Security
Moderate
CVE-2022-22976
was published
for
org.springframework.security:spring-security-core
(Maven)
May 20, 2022
Integer Overflow or Wraparound in Apache Tomcat
Moderate
CVE-2014-0075
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Integer Overflow or Wraparound in JBCrypt
Moderate
CVE-2015-0886
was published
for
org.mindrot:jbcrypt
(Maven)
May 13, 2022
Buffer Overflow in yajl-ruby
Moderate
CVE-2022-24795
was published
for
yajl-ruby
(RubyGems)
Apr 5, 2022
Memory exhaustion in Tensorflow
Moderate
CVE-2022-21733
was published
for
tensorflow
(pip)
Feb 10, 2022
Integer Overflow or Wraparound in TensorFlow
Moderate
GHSA-wcv5-vrvr-3rx2
was published
for
tensorflow
(pip)
Feb 9, 2022
Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC
Moderate
CVE-2021-43784
was published
for
github.com/opencontainers/runc
(Go)
Dec 7, 2021
ProTip!
Advisories are also available from the
GraphQL API