GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,931
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,382
Swift
56
Unreviewed advisories
All unreviewed
5,000+
2,191 advisories
Filter by severity
A race condition in the shared Extreme Platform
ONE IAM Gateway API-key authentication path could...
Moderate
Unreviewed
CVE-2026-9831
was published
May 30, 2026
Gotenberg has a Race Condition via Multipart `downloadFrom` Handling
High
CVE-2026-45742
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 29, 2026
Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to...
Low
Unreviewed
CVE-2026-9959
was published
May 29, 2026
Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-10006
was published
May 29, 2026
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia...
High
Unreviewed
CVE-2025-46284
was published
May 27, 2026
NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could...
Moderate
Unreviewed
CVE-2026-24199
was published
May 26, 2026
An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in...
High
Unreviewed
CVE-2026-46727
was published
May 26, 2026
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14...
Moderate
Unreviewed
CVE-2026-4635
was published
May 26, 2026
ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
Moderate
CVE-2026-46693
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 22, 2026
A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local...
Moderate
Unreviewed
CVE-2026-44059
was published
May 21, 2026
Undefined behavior may result due to a race condition leading to a use-after-free violation. If...
High
Unreviewed
CVE-2026-5947
was published
May 20, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
Moderate
CVE-2026-45712
was published
for
github.com/axllent/mailpit
(Go)
May 19, 2026
The adjustments made for XSA-379 as well as those subsequently becoming
XSA-387 still left a race...
High
Unreviewed
CVE-2026-23558
was published
May 19, 2026
Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact...
High
Unreviewed
CVE-2026-42099
was published
May 19, 2026
NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within...
Moderate
Unreviewed
CVE-2026-32848
was published
May 18, 2026
shopper/framework: Race condition on Discount.usage_limit allows silent over-redemption
Moderate
GHSA-9rh9-hf3w-9fgg
was published
for
shopper/cart
(Composer)
May 18, 2026
A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file...
Low
Unreviewed
CVE-2026-8741
was published
May 17, 2026
Permission control vulnerability in the web. Impact: Successful exploitation of this...
High
Unreviewed
CVE-2026-41964
was published
May 15, 2026
Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to...
High
Unreviewed
CVE-2026-8520
was published
May 14, 2026
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
High
CVE-2026-45675
was published
for
open-webui
(pip)
May 14, 2026
A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server...
Moderate
Unreviewed
CVE-2026-28379
was published
May 13, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2026-34351
was published
May 12, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2026-34342
was published
May 12, 2026
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-34337
was published
May 12, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2026-34334
was published
May 12, 2026
ProTip!
Advisories are also available from the
GraphQL API