GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
90 advisories
Filter by severity
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
Moderate
CVE-2026-48043
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 11, 2026
Spring Data Commons: Denial of Service via excessive memory allocation in projection binding
Moderate
CVE-2026-41721
was published
for
org.springframework.data:spring-data-commons
(Maven)
Jun 10, 2026
Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)
Moderate
CVE-2026-41711
was published
for
org.springframework.data:spring-data-commons
(Maven)
Jun 10, 2026
Spring Framework Denial of Service via Multipart Requests in WebFlux
Moderate
CVE-2026-41840
was published
for
org.springframework:spring-webflux
(Maven)
Jun 9, 2026
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Moderate
CVE-2026-54712
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()
Moderate
CVE-2026-50193
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
Apache Tomcat Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2024-54677
was published
for
org.apache.tomcat:tomcat
(Maven)
Dec 17, 2024
Spring Framework DoS with Multipart Temp Files in WebFlux
Moderate
CVE-2026-22740
was published
for
org.springframework:spring-webflux
(Maven)
Apr 29, 2026
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
Moderate
CVE-2026-47244
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 8, 2026
Netty MQTT: Resource exhaustion in MqttDecoder
Moderate
CVE-2026-44248
was published
for
io.netty:netty-codec-mqtt
(Maven)
May 7, 2026
HTTP/2 Stream Cancellation Attack
Moderate
CVE-2023-44487
was published
for
com.typesafe.akka:akka-http-core
(Go)
Oct 10, 2023
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
Moderate
CVE-2026-22745
was published
for
org.springframework:spring-webflux
(Maven)
Apr 29, 2026
Spring AI Vulnerable to OOM by attacker-controlled PDF
Moderate
CVE-2026-40980
was published
for
org.springframework.ai:spring-ai-pdf-document-reader
(Maven)
Apr 28, 2026
Liferay Portal vulnerable to Denial of Service
Moderate
CVE-2024-26265
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Feb 20, 2024
Eclipse Vert.x vulnerable to a memory leak in TCP servers
Moderate
CVE-2024-1300
was published
for
io.vertx:vertx-core
(Maven)
Apr 2, 2024
Hash collision in typelevel jawn
Moderate
CVE-2022-21653
was published
for
org.typelevel:jawn-parser_0.25
(Maven)
Jan 6, 2022
FS2 half-shutdown of socket during TLS handshake may result in spin loop on opposite side
Moderate
CVE-2025-58369
was published
for
co.fs2:fs2-io_0.26
(Maven)
Sep 5, 2025
Apereo CAS has inefficient regular expression complexity
Moderate
CVE-2025-3985
was published
for
org.apereo.cas:cas-management-webapp-support
(Maven)
Apr 27, 2025
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
Moderate
CVE-2025-48795
was published
for
org.apache.cxf:cxf-core
(Maven)
Jul 15, 2025
jose4j denial of service via specifically crafted JWE
Moderate
CVE-2023-51775
was published
for
org.bitbucket.b_c:jose4j
(Maven)
Feb 29, 2024
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
Moderate
CVE-2024-8184
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Oct 14, 2024
Eclipse Jetty has a denial of service vulnerability on DosFilter
Moderate
CVE-2024-9823
was published
for
org.eclipse.jetty.ee10:jetty-ee10-servlets
(Maven)
Oct 14, 2024
Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
Moderate
CVE-2025-12194
was published
for
org.bouncycastle:bc-fips
(Maven)
Oct 25, 2025
Elasticsearch Uncontrolled Resource Consumption Vulnerability
Moderate
CVE-2024-52979
was published
for
org.elasticsearch:elasticsearch
(Maven)
May 1, 2025
Uncontrolled Resource Consumption in Spray JSON
Moderate
CVE-2018-18855
was published
for
io.spray:spray-json_2.10
(Maven)
Jun 28, 2022
ProTip!
Advisories are also available from the
GraphQL API