Inside the Advisory Database and what happens when vulnerability volume breaks records
The GitHub Advisory Database published 1,560 reviewed advisories in May 2026, a record high. The surge in vulnerability reports has caused delays in publication times.
Intelligence analysis by Llama 3.3 70B

The GitHub Advisory Database is struggling to keep up with a surge in vulnerability reports, causing delays in publication times. The database published 1,560 reviewed advisories in May 2026, a record high.
Imagine you have a big library with lots of books, and each book has a special code that says if it's safe or not. The people who take care of the library are getting too many new books to check, so it's taking them longer to make sure they're safe. This means that some books might be unsafe for a little while longer than usual.
Analysis
The Surge in Vulnerability Reports
The GitHub Advisory Database has seen a significant surge in vulnerability reports, with 1,560 reviewed advisories published in May 2026. This is more than five times the typical monthly output and the highest in its history. The surge is not limited to GitHub, with the volume of reported and published vulnerabilities growing rapidly across the ecosystem.
The increase in vulnerability reports is not just a matter of quantity, but also complexity. Many incoming advisories require more investigation, including package disambiguation, version range reconstruction, and multi-ecosystem advisories. This requires independent verification across multiple data sources and can create a compounding effect, making it harder for curators to keep up.
The Impact on Publication Times
The surge in vulnerability reports has caused delays in publication times. Due to the increased volume and complexity of advisories, curators are taking longer to validate and publish advisory data. This can increase exposure windows, making it more important for maintainers and researchers to coordinate closely and submit complete vulnerability data.
The Importance of Verification
A reviewed advisory is not simply a republished record, but the result of verification. Curators map vulnerabilities to the correct ecosystem package, validate affected and fixed versions against release history, and confirm upstream accuracy. This verification process is crucial for ensuring the accuracy and reliability of advisory data, and skipping it would increase false positives at scale.
Key points
- The GitHub Advisory Database published 1,560 reviewed advisories in May 2026, a record high
- The surge in vulnerability reports is causing delays in publication times
- Verification is crucial for ensuring the accuracy and reliability of advisory data
If the GitHub Advisory Database can adapt to the surge in vulnerability reports, it could lead to improved data quality and more effective vulnerability management. By prioritizing verification and coordination, maintainers and researchers can help ensure that advisory data is accurate and reliable.
If the surge in vulnerability reports continues to overwhelm the GitHub Advisory Database, it could lead to delays and inaccuracies in advisory data. This could increase exposure windows and make it harder for maintainers and researchers to keep up with the latest vulnerabilities.
