GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
503 advisories
Filter by severity
Wagtail: Denial of service via unbounded filter specs in the image preview
Moderate
CVE-2026-54260
was published
for
wagtail
(pip)
Aug 20, 2026
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
Moderate
CVE-2026-53941
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
Aug 19, 2026
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
Moderate
CVE-2026-68924
was published
for
mobsf
(pip)
Aug 18, 2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Moderate
CVE-2026-73559
was published
for
vllm
(pip)
Aug 13, 2026
pypdf: Possible large memory usage for large /ToUnicode streams
Moderate
CVE-2026-71870
was published
for
pypdf
(pip)
Aug 7, 2026
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
Moderate
CVE-2026-71310
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Moderate
CVE-2026-70489
was published
for
open-webui
(pip)
Aug 4, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Moderate
CVE-2026-52857
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
Moderate
CVE-2026-63119
was published
for
mcp
(RubyGems)
Jul 30, 2026
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Moderate
CVE-2026-54712
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Moderate
CVE-2026-55497
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Moderate
GHSA-r292-9mhp-454m
was published
for
tar
(npm)
Jul 24, 2026
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
Moderate
CVE-2026-55595
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
Moderate
CVE-2026-55594
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
pypdf: Possible long runtimes for repeated malformed cross-reference entries
Moderate
CVE-2026-59937
was published
for
pypdf
(pip)
Jul 23, 2026
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Moderate
CVE-2026-59942
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
Moderate
CVE-2026-59941
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Gitea SSH Key Parser Denial of Service
Moderate
CVE-2026-56657
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
Moderate
GHSA-mwf2-3pr3-8698
was published
for
axios
(npm)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
Moderate
CVE-2026-59868
was published
for
js-yaml
(npm)
Jul 20, 2026
Axios: Excessive recursion in formDataToJSON can cause denial of service
Moderate
GHSA-42h9-826w-cgv3
was published
for
axios
(npm)
Jul 20, 2026
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
Moderate
GHSA-pmv8-rq9r-6j72
was published
for
axios
(npm)
Jul 20, 2026
vLLM: Speech-to-text upload size limit is enforced after full UploadFile read
Moderate
CVE-2026-55646
was published
for
vllm
(pip)
Jul 17, 2026
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files
Moderate
GHSA-xg43-5579-qw6v
was published
for
adawolfa/isdoc
(Composer)
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Moderate
CVE-2026-54465
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
ProTip!
Advisories are also available from the
GraphQL API