GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
260 advisories
Filter by severity
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
High
CVE-2026-59939
was published
for
httplib2
(pip)
Jul 24, 2026
Wagtail: Denial of service via unbounded filter specs in the image preview
Moderate
CVE-2026-54260
was published
for
wagtail
(pip)
Aug 20, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
High
CVE-2026-5497
was published
for
vllm
(pip)
Jun 11, 2026
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
Moderate
CVE-2026-68924
was published
for
mobsf
(pip)
Aug 18, 2026
sqlparse: Quadratic O(n²) DoS in group_comments
High
CVE-2026-71491
was published
for
sqlparse
(pip)
Aug 17, 2026
pyasn1 has a DoS vulnerability in decoder
High
CVE-2026-23490
was published
for
pyasn1
(pip)
Jan 16, 2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Moderate
CVE-2026-73559
was published
for
vllm
(pip)
Aug 13, 2026
libp2p: yamux connection DoS via oversized data frame
High
CVE-2026-73568
was published
for
libp2p
(pip)
Jul 24, 2026
pypdf: Possible large memory usage for large /ToUnicode streams
Moderate
CVE-2026-71870
was published
for
pypdf
(pip)
Aug 7, 2026
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
High
CVE-2026-70646
was published
for
aiosend
(pip)
May 22, 2026
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Moderate
CVE-2026-70489
was published
for
open-webui
(pip)
Aug 4, 2026
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
High
CVE-2026-69249
was published
for
cryptography
(pip)
Aug 3, 2026
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
High
CVE-2026-69244
was published
for
aiohttp
(pip)
Aug 3, 2026
Docling: Unsafe URI and Path Handling in HTML Backend
High
CVE-2026-47214
was published
for
docling
(pip)
Jun 3, 2026
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
High
CVE-2026-59884
was published
for
pyasn1
(pip)
Jul 21, 2026
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
High
CVE-2026-53505
was published
for
thumbor
(pip)
Jul 31, 2026
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
High
CVE-2026-53504
was published
for
thumbor
(pip)
Jul 31, 2026
hermes-agent has an Uncontrolled Resource Consumption issue
Moderate
CVE-2026-10224
was published
for
hermes-agent
(pip)
Jun 1, 2026
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
pypdf: Possible infinite loop for not terminated inline images
High
CVE-2026-59936
was published
for
pypdf
(pip)
Jul 23, 2026
pypdf: Possible long runtimes for repeated malformed cross-reference entries
Moderate
CVE-2026-59937
was published
for
pypdf
(pip)
Jul 23, 2026
pyasn1: Uncontrolled resource consumption when converting decoded REAL values
High
CVE-2026-59886
was published
for
pyasn1
(pip)
Jul 21, 2026
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
High
CVE-2026-59885
was published
for
pyasn1
(pip)
Jul 21, 2026
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
High
CVE-2026-59200
was published
for
Pillow
(pip)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API