Vendor Security Advisories

Security advisories straight from the source — Microsoft, Red Hat, GitHub, and beyond. Searchable, indexed, and live the moment vendors publish.

Live40,232 advisories tracked505 disclosed before NVD3,393 Critical18,601 High13,459 Medium2,011 Low
10 vendors tracked· 1,593 ingested in last 24h← Back to CVE Pulse

🔔 Vendor advisory alerts

Catch vendor-disclosed advisories the day they ship

Vendors like Microsoft, Red Hat, and GitHub publish security advisories days to weeks before NVD assigns a CVE. Subscribe to get these the moment we ingest them.

  • Microsoft MSRC, Red Hat RHSA, GitHub GHSA — full vendor coverage
  • Embargo-window disclosures included (Pre-CVE advisories)
  • Real-time, daily, weekly, or monthly cadence

Free · Unsubscribe in one click · No marketing email

Browse by vendor

10 active · 10 tracked
Disclosed before NVD assigned a CVE-ID505 total

These advisories were published by the upstream vendor before NVD assigned a CVE-ID. Customers received the email on day zero — everyone else has to wait days to weeks for NVD to catch up.

GHSA-f88m-g3jw-g9cjGitHub

sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591

HIGHJul 21, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-8r6m-32jq-jx6qGitHub

fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits

HIGHJul 21, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-rwj8-pgh3-r573GitHub7.5

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

HIGHJul 21, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-cj75-f6xr-r4g7GitHub

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

MEDIUMJul 21, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-9mqv-5hh9-4cggGitHub5.3

Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake

MEDIUMJul 21, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-hrxh-6v49-42gfGitHub

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

HIGHJul 21, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-5qhf-9phg-95m2GitHub

Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

LOWJul 21, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-9wjq-cp2p-hrgfGitHub4.7

Loofah: SVG `href` attribute bypasses local-reference restriction

MEDIUMJul 21, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-2rp8-mm9q-fp49GitHub5.7

TypeORM: migration:generate template-literal code injection

MEDIUMJul 21, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-r7wm-3cxj-wff9GitHub

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

HIGHJul 21, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-rjvx-x5h2-6px5GitHub

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions

MEDIUMJul 21, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-956x-8gvw-wg5vGitHub8.4

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

HIGHJul 21, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
Most Recent Vendor Advisoriestop 12

The newest 12 advisories ingested from any tracked vendor — refreshed every two minutes.

RHSA-2026:43513Red Hat7.5

Red Hat Security Advisory: openssl security update

MEDIUMJul 22, 2026View details →
GHSA-vhcw-f978-xjjgGitHub

n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site...

HIGHJul 22, 2026View details →
GHSA-6mxq-jr92-3h2rGitHub

Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the...

MEDIUMJul 22, 2026View details →
GHSA-7m3p-wc52-rmc6GitHub

Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces...

MEDIUMJul 22, 2026View details →
GHSA-rhg6-2vjh-j5qcGitHub

Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an...

HIGHJul 22, 2026View details →
GHSA-38mm-mxvc-j98qGitHub8.8

The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw...

HIGHJul 22, 2026View details →
GHSA-725q-c4vp-q4cgGitHub

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone...

HIGHJul 22, 2026View details →
GHSA-mhvh-gwhr-76pwGitHub

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability:...

MEDIUMJul 22, 2026View details →
GHSA-qv24-466w-wgvjGitHub7.2

There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow...

HIGHJul 22, 2026View details →
GHSA-fmvg-vhqq-r2mjGitHub

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node...

MEDIUMJul 22, 2026View details →
GHSA-m7jc-p4hf-xhwqGitHub

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed...

HIGHJul 22, 2026View details →
GHSA-5vfw-jc4p-fj39GitHub

n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and...

MEDIUMJul 22, 2026View details →

Browse all advisories

Severity:
Loading…

Frequently asked questions

What is a vendor security advisory?
A vendor security advisory is an official disclosure published by the software or hardware vendor itself — Microsoft's MSRC, Red Hat Product Security, GitHub Security Advisories, and others. Vendor advisories typically include a CVE-ID once one is assigned, vendor-specific remediation steps, and the exact list of affected product builds — all of which the upstream NVD entry may not yet have.
How is this different from the NVD CVE feed?
NVD publishes CVEs after the CVE Numbering Authority coordinates disclosure with the vendor. Vendors often notify customers days to weeks before NVD's public record. This feed captures the vendor side directly, surfacing embargo-window disclosures that don't yet appear in NVD or GitHub Advisory Database.
Which vendors are tracked?
Microsoft Security Response Center (MSRC), Red Hat Product Security (RHSA via CSAF), and GitHub Security Advisories (GHSA) are live today. Apple, AWS, GCP, Azure, VMware, HashiCorp, Atlassian, GitLab, Grafana, and Cisco are tracked vendors with pollers in development.
How often is the feed updated?
GitHub GHSA is polled every hour for fast embargo-window coverage. Red Hat CSAF and Microsoft MSRC are polled every six hours. Each advisory's first-seen timestamp is preserved separately from the vendor's published-at so you can audit how quickly we caught it.
Does the feed include CVSS scores and remediation guidance?
Yes when the vendor publishes them. CVSS v3 scores, severity bands (Critical/High/Medium/Low), the full list of affected product builds, vendor-specific patch / mitigation steps, and authoritative reference URLs are surfaced on every advisory detail page. Fields are blank when the vendor's own disclosure did not include them.
Is this feed free to use?
Yes. All pages on /pulse/vendor-advisories are free to read and link to. The underlying advisory data is published by each vendor under their own terms — EchelonGraph aggregates and normalises it for discoverability.