GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
275 advisories
Filter by severity
Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who...
Moderate
Unreviewed
CVE-2026-79267
was published
Aug 25, 2026
Race condition in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-79196
was published
Aug 25, 2026
Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65...
Moderate
Unreviewed
CVE-2026-79089
was published
Aug 25, 2026
Race condition in Permissions in Google Chrome on on Android prior to 152.0.7977.65 allowed a...
Moderate
Unreviewed
CVE-2026-79046
was published
Aug 25, 2026
Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-78991
was published
Aug 25, 2026
Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2026-79017
was published
Aug 25, 2026
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
Moderate
CVE-2026-55535
was published
for
PraisonAI
(pip)
Aug 25, 2026
Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook...
Moderate
Unreviewed
CVE-2026-56708
was published
Aug 25, 2026
Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote...
Moderate
Unreviewed
CVE-2026-73829
was published
Aug 19, 2026
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Moderate
CVE-2026-70667
was published
for
lemur
(pip)
Aug 18, 2026
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Moderate
CVE-2026-53708
was published
for
mcp-contextforge-gateway
(pip)
Aug 14, 2026
Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions...
Moderate
Unreviewed
CVE-2026-20908
was published
Aug 11, 2026
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could...
Moderate
Unreviewed
CVE-2026-5303
was published
Aug 11, 2026
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could...
Moderate
Unreviewed
CVE-2026-6505
was published
Aug 11, 2026
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles...
Moderate
Unreviewed
CVE-2026-19079
was published
Aug 7, 2026
Electron: Parent process code-sign check is spoofable
Moderate
CVE-2026-70597
was published
for
electron
(npm)
Aug 5, 2026
Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target...
Moderate
Unreviewed
CVE-2026-71210
was published
Aug 5, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling
Moderate
CVE-2026-53945
was published
for
ghost
(npm)
Aug 4, 2026
Open WebUI: DNS Rebinding SSRF Bypass
Moderate
CVE-2026-54020
was published
for
open-webui
(pip)
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition...
Moderate
Unreviewed
CVE-2026-47621
was published
Aug 4, 2026
A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync...
Moderate
Unreviewed
CVE-2026-58041
was published
Aug 4, 2026
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an...
Moderate
Unreviewed
CVE-2026-66314
was published
Aug 4, 2026
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename...
Moderate
Unreviewed
CVE-2026-18477
was published
Aug 3, 2026
In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This...
Moderate
Unreviewed
CVE-2026-20492
was published
Aug 3, 2026
In display, there is a possible escalation of privilege due to a race condition. This could lead...
Moderate
Unreviewed
CVE-2026-20474
was published
Aug 3, 2026
ProTip!
Advisories are also available from the
GraphQL API