GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,737
Maven
5,000+
npm
4,337
NuGet
765
pip
4,112
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
147 advisories
Filter by severity
Babylon Nil BlockHash in BLS vote extensions triggers panics in consensus handlers
High
GHSA-m6wq-66p2-c8pc
was published
for
github.com/babylonlabs-io/babylon
(Go)
Dec 8, 2025
Envoy crashes when JWT authentication is configured with the remote JWKS fetching
Moderate
CVE-2025-64527
was published
for
github.com/envoyproxy/envoy
(Go)
Dec 5, 2025
Nokogiri NULL Pointer Dereference
High
CVE-2018-14404
was published
for
nokogiri
(RubyGems)
Jan 17, 2019
OSV-SCALIBR has NULL Pointer Dereference
Low
CVE-2025-13425
was published
for
github.com/google/osv-scalibr
(Go)
Nov 20, 2025
MLX has Wild Pointer Dereference in load_gguf()
Moderate
CVE-2025-62609
was published
for
mlx
(pip)
Nov 21, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests
Moderate
CVE-2025-59836
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
openssl-src subject to Invalid pointer dereference in `d2i_PKCS7` functions
High
CVE-2023-0216
was published
for
openssl-src
(Rust)
Feb 8, 2023
openssl-src contains `NULL` dereference during PKCS7 data verification
High
CVE-2023-0401
was published
for
openssl-src
(Rust)
Feb 8, 2023
lxml NULL Pointer Dereference allows attackers to cause a denial of service
Moderate
CVE-2022-2309
was published
for
lxml
(pip)
Jul 6, 2022
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
Moderate
CVE-2023-49083
was published
for
cryptography
(pip)
Nov 28, 2023
Null pointer dereference in PKCS12 parsing
Moderate
CVE-2024-0727
was published
for
cryptography
(pip)
Jan 26, 2024
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload
High
CVE-2025-59537
was published
for
github.com/argoproj/argo-cd
(Go)
Sep 30, 2025
Nil dereference in NATS JWT, DoS of nats-server
High
CVE-2020-26521
was published
for
github.com/nats-io/jwt
(Go)
Feb 11, 2022
Nil dereference in NATS JWT causing DoS of nats-server
High
GHSA-hmm9-r2m2-qg9w
was published
for
github.com/nats-io/nats-server/v2
(Go)
May 21, 2021
@plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user
High
CVE-2025-61668
was published
for
@plone/volto
(npm)
Oct 1, 2025
DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an error
Moderate
CVE-2025-59351
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Mattermost has Potential Server Crash due to Unvalidated Import Data
Moderate
CVE-2025-8402
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Versity panic induced by AWS chunked data sent to port
High
GHSA-v2ch-c8v8-fgr7
was published
for
github.com/versity/versitygw
(Go)
Aug 29, 2025
Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers
High
CVE-2021-22570
was published
for
Google.Protobuf
(Composer)
Jan 27, 2022
•
withdrawn
MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput
Low
CVE-2025-53011
was published
for
MaterialX
(pip)
Jul 31, 2025
MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return
Low
CVE-2025-53010
was published
for
MaterialX
(pip)
Jul 31, 2025
OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode
Moderate
CVE-2025-48073
was published
for
OpenEXR
(pip)
Jul 31, 2025
Withdrawn Advisory: microlight.js has a null pointer dereference vulnerability
Low
CVE-2025-45525
was published
for
microlight
(npm)
Jun 17, 2025
•
withdrawn
Ollama Denial of Service (DoS) via Null Pointer Dereference
High
CVE-2025-0312
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
openssl-src subject to NULL dereference validating DSA public key
High
CVE-2023-0217
was published
for
openssl-src
(Rust)
Feb 8, 2023
ProTip!
Advisories are also available from the
GraphQL API