Paste advisory identifiers in any mix. This page classifies each one, validates the format character by character, and builds the canonical lookup links. Everything runs locally and no request is made to any advisory database.
Type counts and failure counts overlap on purpose. A malformed GHSA id is still counted as a GHSA id and again under failed checks. Unrecognised means the token matched no known scheme at all. Flagged means the format is legal but something about the value is implausible.
GHSA-2222-2222-2222 is perfectly legal and almost certainly does not exist. Only the linked databases can confirm a real advisory.A CVE identifier has the shape CVE-YYYY-NNNN. The year segment is exactly four digits and the sequence segment is four digits or more. The four digit floor is why you see CVE-2021-0001 rather than CVE-2021-1. There is no upper bound on the sequence, which is why identifiers such as CVE-2022-42969 with five digits, or six digit ids, are entirely normal.
Two things people routinely read into a CVE id that are not there. The year is the year the identifier was reserved by a numbering authority, not the year the bug was found, disclosed, or fixed, so an id issued in December and published the following March keeps the older year. And the sequence number is assigned in blocks to numbering authorities, so a low number does not mean the bug was found early in the year and a high number does not mean it was found late.
This page flags a year before 1999 because the CVE programme launched that year, and a year more than one calendar year ahead of today because identifiers are reserved a little ahead but not far ahead. Both are flagged as implausible rather than invalid, since the format itself is still legal.
A GitHub Security Advisory identifier has the shape GHSA-xxxx-xxxx-xxxx, that is the literal prefix followed by three groups of exactly four characters. The groups are not hexadecimal and not ordinary base32. GitHub draws them from a reduced twenty character alphabet:
Every vowel is missing, which stops the generator producing real words by accident. So are the characters that people misread or mistype most often. There is no 0 and no o, no 1 and no l, and no i, b, d, k, n, s, t, u, y, or z. Twelve characters from a twenty character alphabet gives twenty to the twelfth power, which is 4,096,000,000,000,000 possible identifiers.
That reduced alphabet is exactly what makes offline validation worth doing. A GHSA id contains no checksum, so a mistyped identifier that happens to stay inside the alphabet is undetectable here and will simply return nothing on GitHub. But a very large share of real typos land on a character the alphabet forbids, most often a zero typed for a q, an l or 1 typed into a group, or an o for a q. Those are caught here instantly with the exact position, instead of showing up as a silent empty page.
The canonical written form uses an uppercase GHSA prefix and a lowercase body. Uppercase input is accepted and normalised, and the normalised form is what the links use.
OSV.dev aggregates many databases and each contributing database uses its own prefix, so an OSV identifier looks like PREFIX-YEAR-NUMBER. A GHSA id is itself a valid OSV id, since the GitHub Advisory Database is one of the contributing sources. The prefixes this page recognises:
| Prefix | Source database |
|---|---|
GHSA | GitHub Advisory Database |
PYSEC | Python Packaging Advisory Database |
GO | Go Vulnerability Database |
RUSTSEC | RustSec Advisory Database |
OSV | OSS-Fuzz findings |
MAL | Malicious Packages database |
CURL | curl project advisories |
HSEC | Haskell Security Advisories |
RSEC | R Consortium Advisory Database |
PSF | Python Software Foundation advisories |
UVI | Unified Vulnerability Identifiers |
GSD | Global Security Database |
USN | Ubuntu Security Notices |
DSA, DLA | Debian security advisories |
RHSA | Red Hat Security Advisories |
ALSA | AlmaLinux Security Advisories |
One identifier frequently maps to several. The same flaw can hold a CVE from the vendor, a GHSA from GitHub, and a distribution advisory id, all at once. That is why every result below links out to more than one database rather than picking a winner.
The common workflow is a dependency scanner output or a triage ticket holding thirty identifiers in mixed formats, some of them wrapped in URLs and some duplicated across findings. Paste the lot. The tool strips URL wrappers and surrounding punctuation, pulls the identifier out, folds duplicates together case insensitively, counts what you actually have by type, and tells you which entries will not resolve anywhere because they are malformed.