GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
Code Execution Through IIFE in serialize-to-js
Critical
CVE-2017-5954
was published
for
serialize-to-js
(npm)
Jul 18, 2018
Code Execution through IIFE in node-serialize
Critical
CVE-2017-5941
was published
for
node-serialize
(npm)
Jul 18, 2018
Remote Code Execution in scratch-vm
Critical
CVE-2020-14000
was published
for
scratch-vm
(npm)
Jul 27, 2020
Insecure serialization leading to RCE in serialize-javascript
High
CVE-2020-7660
was published
for
serialize-javascript
(npm)
Aug 11, 2020
Deserialization of Untrusted Data in bson
Critical
CVE-2020-7610
was published
for
bson
(npm)
May 7, 2021
Deserialization of Untrusted Data in msgpack
Critical
CVE-2021-23410
was published
for
msgpack
(npm)
Jul 26, 2021
•
withdrawn
Deserialization of Untrusted Data in bson
Moderate
CVE-2019-2391
was published
for
bson
(npm)
Feb 10, 2022
Unsanitized JavaScript code injection possible in gatsby-plugin-mdx
High
CVE-2022-25863
was published
for
gatsby-plugin-mdx
(npm)
Jun 3, 2022
replicator vulnerable to Deserialization of Untrusted Data
Critical
CVE-2021-33420
was published
for
replicator
(npm)
Dec 15, 2022
kurwov vulnerable to Denial of Service due to improper data sanitization
Moderate
CVE-2024-34075
was published
for
kurwov
(npm)
May 3, 2024
Next.js is vulnerable to RCE in React flight protocol
Critical
CVE-2025-66478
was published
for
next
(npm)
Dec 3, 2025
React Server Components are Vulnerable to RCE
Critical
CVE-2025-55182
was published
for
react-server-dom-parcel
(npm)
Dec 3, 2025
React Server Components are Vulnerable to RCE
Critical
GHSA-fmh4-wr37-44fp
was published
for
@vitejs/plugin-rsc
(npm)
Dec 3, 2025
ProTip!
Advisories are also available from the
GraphQL API