Vendor Security Advisories

Security advisories straight from the source — Microsoft, Red Hat, GitHub, and beyond. Searchable, indexed, and live the moment vendors publish.

Live41,868 advisories tracked629 disclosed before NVD3,597 Critical19,214 High13,989 Medium2,096 Low
10 vendors tracked· 41 ingested in last 24h← Back to CVE Pulse

🔔 Vendor advisory alerts

Catch vendor-disclosed advisories the day they ship

Vendors like Microsoft, Red Hat, and GitHub publish security advisories days to weeks before NVD assigns a CVE. Subscribe to get these the moment we ingest them.

  • Microsoft MSRC, Red Hat RHSA, GitHub GHSA — full vendor coverage
  • Embargo-window disclosures included (Pre-CVE advisories)
  • Real-time, daily, weekly, or monthly cadence

Free · Unsubscribe in one click · No marketing email

Browse by vendor

10 active · 10 tracked
Disclosed before NVD assigned a CVE-ID629 total

These advisories were published by the upstream vendor before NVD assigned a CVE-ID. Customers received the email on day zero — everyone else has to wait days to weeks for NVD to catch up.

GHSA-6vch-q96h-7gc3GitHub

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

HIGHJul 24, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-8q49-2h5h-434xGitHub5.9

FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller

MEDIUMJul 24, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-jpcw-4wr7-c3vqGitHub5.3

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

MEDIUMJul 24, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-xg4h-6gfc-h4m8GitHub

etcd: Watch API authorization bypass via open-ended range requests

HIGHJul 24, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-hmj8-5xmh-5573GitHub7.5

libp2p: yamux connection DoS via oversized data frame

HIGHJul 24, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-3r53-75j5-3g7jGitHub5.6

Quasar: Prototype pollution in the extend() utility

MEDIUMJul 24, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-6xj8-qv9j-xcjqGitHub7.8

Oh My Posh: Arbitrary command execution via template injection in the path segment

HIGHJul 24, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-fwjx-9p69-h25hGitHub6.1

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

MEDIUMJul 24, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-fp43-vj7g-pg92GitHub7.5

OmniFaces: Forged combined-resource IDs and related output/push boundaries

HIGHJul 24, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-gm3r-q2wp-hw87GitHub

Shescape: Quadratic-time denial of service in the flag-protection

HIGHJul 24, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-q53c-4prm-w95qGitHub

Shescape: Home-directory disclosure in assignment context on Unix with Dash

MEDIUMJul 24, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
GHSA-w4hw-qcx7-56prGitHub

Shescape: Shell injection via unescaped parentheses on Windows with CMD

CRITICALJul 24, 2026View details →
⏳ Pre-CVE · vendor-disclosed before NVD
Most Recent Vendor Advisoriestop 12

The newest 12 advisories ingested from any tracked vendor — refreshed every two minutes.

GHSA-h334-888w-8prrGitHub5.3

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function...

MEDIUMJul 27, 2026View details →
GHSA-92r6-r5fj-xg82GitHub5.3

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function...

MEDIUMJul 27, 2026View details →
GHSA-mrjw-v97f-vmwhGitHub

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting...

HIGHJul 27, 2026View details →
RHSA-2026:46391Red Hat7.5

Red Hat Security Advisory: grafana security, bug fix, and enhancement update

HIGHJul 27, 2026View details →
RHSA-2026:46377Red Hat7.8

Red Hat Security Advisory: tigervnc security update

HIGHJul 27, 2026View details →
GHSA-vx88-58rg-q48hGitHub5.4

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...

MEDIUMJul 26, 2026View details →
GHSA-26c6-hf7j-9wr3GitHub7.4

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an...

HIGHJul 26, 2026View details →
GHSA-cwgc-vfm7-rq3rGitHub7.4

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...

HIGHJul 26, 2026View details →
GHSA-r5ff-hq22-rhgvGitHub8.3

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash,...

HIGHJul 26, 2026View details →
GHSA-gwhc-vprp-gfcgGitHub8.1

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and...

HIGHJul 26, 2026View details →
GHSA-5q2x-g6w4-m2qgGitHub6.3

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function...

LOWJul 26, 2026View details →
GHSA-cjfh-hv3c-xcfgGitHub4.3

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the...

LOWJul 26, 2026View details →

Browse all advisories

Severity:
Loading…

Frequently asked questions

What is a vendor security advisory?
A vendor security advisory is an official disclosure published by the software or hardware vendor itself — Microsoft's MSRC, Red Hat Product Security, GitHub Security Advisories, and others. Vendor advisories typically include a CVE-ID once one is assigned, vendor-specific remediation steps, and the exact list of affected product builds — all of which the upstream NVD entry may not yet have.
How is this different from the NVD CVE feed?
NVD publishes CVEs after the CVE Numbering Authority coordinates disclosure with the vendor. Vendors often notify customers days to weeks before NVD's public record. This feed captures the vendor side directly, surfacing embargo-window disclosures that don't yet appear in NVD or GitHub Advisory Database.
Which vendors are tracked?
Microsoft Security Response Center (MSRC), Red Hat Product Security (RHSA via CSAF), and GitHub Security Advisories (GHSA) are live today. Apple, AWS, GCP, Azure, VMware, HashiCorp, Atlassian, GitLab, Grafana, and Cisco are tracked vendors with pollers in development.
How often is the feed updated?
GitHub GHSA is polled every hour for fast embargo-window coverage. Red Hat CSAF and Microsoft MSRC are polled every six hours. Each advisory's first-seen timestamp is preserved separately from the vendor's published-at so you can audit how quickly we caught it.
Does the feed include CVSS scores and remediation guidance?
Yes when the vendor publishes them. CVSS v3 scores, severity bands (Critical/High/Medium/Low), the full list of affected product builds, vendor-specific patch / mitigation steps, and authoritative reference URLs are surfaced on every advisory detail page. Fields are blank when the vendor's own disclosure did not include them.
Is this feed free to use?
Yes. All pages on /pulse/vendor-advisories are free to read and link to. The underlying advisory data is published by each vendor under their own terms — EchelonGraph aggregates and normalises it for discoverability.