Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

53 advisories

Loading
SGLang is Vulnerable to DoS via the data_hash Function Low
CVE-2026-10775 was published for sglang (pip) Jun 4, 2026
Socket.IO: Engine.IO Polling Transport Connection Exhaustion High
CVE-2026-59725 was published for engine.io (npm) Jul 20, 2026
hibrian827 Credited to hibrian827
bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV Map Low
CVE-2026-11312 was published for infinistore (pip) Jun 5, 2026
Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read) Moderate
CVE-2025-11000 was published for openbabel (pip) Jul 1, 2026
Duplicate Advisory: Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read) Low
GHSA-7x26-54jj-cvhr was published for openbabel (pip) Sep 26, 2025 withdrawn
Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt Moderate
CVE-2025-10999 was published for openbabel (pip) Jul 1, 2026
Duplicate Advisory: Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt Low
GHSA-62mq-grc2-53j3 was published for openbabel (pip) Sep 26, 2025 withdrawn
Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines Low
CVE-2025-10998 was published for openbabel (pip) Jul 1, 2026
Duplicate Advisory: Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines Low
GHSA-hvp2-4h2f-26w4 was published for openbabel (pip) Sep 26, 2025 withdrawn
Duplicate Advisory: Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence Low
GHSA-fg6r-xgp8-x64r was published for openbabel (pip) Mar 2, 2026 withdrawn
vllm has Improper Resource Shutdown or Release Moderate
CVE-2026-9540 was published for vllm (pip) May 26, 2026
Undertow MadeYouReset HTTP/2 DDoS Vulnerability High
CVE-2025-9784 was published for io.undertow:undertow-core (Maven) Sep 2, 2025
fawind Credited to fawind
aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect Low
CVE-2026-54280 was published for aiohttp (pip) Jun 15, 2026
denyspakizh-tob Credited to denyspakizh-tob and bdraco bdraco bdraco
BoxLite has a Timeout Bypass Vulnerability Moderate
CVE-2026-47213 was published for boxlite (pip) May 29, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and A7um keenanwgn keenanwgn
A7um A7um
Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode) High
CVE-2026-45090 was published for github.com/hahwul/dalfox (Go) May 12, 2026
bugbunny-research Credited to bugbunny-research
PyTorch susceptible to local Denial of Service Low
CVE-2025-2953 was published for torch (pip) Mar 30, 2025
AMF Vulnerable to Improper Resource Shutdown or Release Low
CVE-2026-8783 was published for github.com/omec-project/amf (Go) May 18, 2026
AMF Vulnerable to Improper Resource Shutdown or Release Low
CVE-2026-8782 was published for github.com/omec-project/amf (Go) May 18, 2026
AMF Vulnerable to Improper Resource Shutdown or Release Low
CVE-2026-8781 was published for github.com/omec-project/amf (Go) May 18, 2026
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release Low
CVE-2025-61795 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Oct 27, 2025
tkwilli94 Credited to tkwilli94
Apache Tomcat Improper Resource Shutdown or Release vulnerability High
CVE-2025-48989 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Aug 13, 2025
snieguu Credited to snieguu
GoBGP has an Improper Resource Shutdown or Release Moderate
CVE-2026-7734 was published for github.com/osrg/gobgp/v4 (Go) May 4, 2026
YLChen-007 Credited to YLChen-007
Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensions Moderate
CVE-2026-34404 was published for nuxt-og-image (npm) Mar 31, 2026
Free5GC AMF is vulnerable to DoS through its HandleRegistrationComplete function Moderate
CVE-2026-4531 was published for github.com/free5gc/amf (Go) Mar 22, 2026
ProTip! Advisories are also available from the GraphQL API