GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,538
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
70 advisories
Filter by severity
n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
High
CVE-2026-42236
was published
for
n8n
(npm)
Apr 29, 2026
OpenClaw: Voice-call realtime WebSocket accepted oversized frames
High
CVE-2026-42437
was published
for
openclaw
(npm)
Apr 17, 2026
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
High
CVE-2026-41324
was published
for
basic-ftp
(npm)
Apr 16, 2026
MCP-Framework: Unbounded memory allocation in readRequestBody allows denial of service via HTTP transport
High
CVE-2026-39313
was published
for
mcp-framework
(npm)
Apr 16, 2026
Nest Affected by DoS via Recursive handleData in JsonSocket (TCP Transport)
High
CVE-2026-40879
was published
for
@nestjs/microservices
(npm)
Apr 14, 2026
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
High
CVE-2026-40073
was published
for
@sveltejs/kit
(npm)
Apr 10, 2026
Next.js has a Denial of Service with Server Components
High
GHSA-q4gf-8mx6-v5v3
was published
for
next
(npm)
Apr 10, 2026
Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
High
CVE-2026-34148
was published
for
@fedify/fedify
(npm)
Apr 7, 2026
Directus: Unauthenticated Denial of Service via GraphQL Alias Amplification of Expensive Health Check Resolver
High
GHSA-6q22-g298-grjh
was published
for
directus
(npm)
Apr 4, 2026
Duplicate Advisory: OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion
High
GHSA-c447-w54g-f55j
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure
High
CVE-2026-35633
was published
for
openclaw
(npm)
Mar 26, 2026
Duplicate Advisory: OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channels
High
GHSA-xq3g-m3j8-2vmm
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion
High
CVE-2026-32980
was published
for
openclaw
(npm)
Mar 16, 2026
Uncontrolled memory allocation via crafted SVG dimensions in @dicebear/converter
High
CVE-2026-29112
was published
for
@dicebear/converter
(npm)
Mar 16, 2026
Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API
High
CVE-2026-30946
was published
for
parse-server
(npm)
Mar 11, 2026
express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network
High
CVE-2026-30827
was published
for
express-rate-limit
(npm)
Mar 6, 2026
Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
High
CVE-2026-27601
was published
for
underscore
(npm)
Mar 3, 2026
OpenClaw voice-call media stream validated streams after upgrade, which could allow pre-start unauthenticated sockets to increase resource pressure
High
CVE-2026-32062
was published
for
@openclaw/voice-call
(npm)
Mar 2, 2026
OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channels
High
CVE-2026-32049
was published
for
openclaw
(npm)
Mar 2, 2026
jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions
High
CVE-2026-25535
was published
for
jspdf
(npm)
Feb 19, 2026
AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type Detection
High
CVE-2026-25762
was published
for
@adonisjs/bodyparser
(npm)
Feb 6, 2026
jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder
High
CVE-2026-24133
was published
for
jspdf
(npm)
Feb 2, 2026
Seroval affected by Denial of Service via Deeply Nested Objects
High
CVE-2026-24006
was published
for
seroval
(npm)
Jan 22, 2026
Seroval affected by Denial of Service via Array serialization
High
CVE-2026-23957
was published
for
seroval
(npm)
Jan 21, 2026
Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding
High
CVE-2025-68272
was published
for
signalk-server
(npm)
Jan 2, 2026
ProTip!
Advisories are also available from the
GraphQL API