Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

53 advisories

Loading
Socket.IO: Engine.IO Polling Transport Connection Exhaustion High
CVE-2026-59725 was published for engine.io (npm) Jul 20, 2026
hibrian827 Credited to hibrian827
Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read) Moderate
CVE-2025-11000 was published for openbabel (pip) Jul 1, 2026
Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt Moderate
CVE-2025-10999 was published for openbabel (pip) Jul 1, 2026
Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines Low
CVE-2025-10998 was published for openbabel (pip) Jul 1, 2026
aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect Low
CVE-2026-54280 was published for aiohttp (pip) Jun 15, 2026
denyspakizh-tob Credited to denyspakizh-tob and bdraco bdraco bdraco
bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV Map Low
CVE-2026-11312 was published for infinistore (pip) Jun 5, 2026
SGLang is Vulnerable to DoS via the data_hash Function Low
CVE-2026-10775 was published for sglang (pip) Jun 4, 2026
BoxLite has a Timeout Bypass Vulnerability Moderate
CVE-2026-47213 was published for boxlite (pip) May 29, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and A7um keenanwgn keenanwgn
A7um A7um
vllm has Improper Resource Shutdown or Release Moderate
CVE-2026-9540 was published for vllm (pip) May 26, 2026
AMF Vulnerable to Improper Resource Shutdown or Release Low
CVE-2026-8783 was published for github.com/omec-project/amf (Go) May 18, 2026
AMF Vulnerable to Improper Resource Shutdown or Release Low
CVE-2026-8781 was published for github.com/omec-project/amf (Go) May 18, 2026
AMF Vulnerable to Improper Resource Shutdown or Release Low
CVE-2026-8782 was published for github.com/omec-project/amf (Go) May 18, 2026
Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode) High
CVE-2026-45090 was published for github.com/hahwul/dalfox (Go) May 12, 2026
bugbunny-research Credited to bugbunny-research
GoBGP has an Improper Resource Shutdown or Release Moderate
CVE-2026-7734 was published for github.com/osrg/gobgp/v4 (Go) May 4, 2026
Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensions Moderate
CVE-2026-34404 was published for nuxt-og-image (npm) Mar 31, 2026
YLChen-007 Credited to YLChen-007
Free5GC AMF is vulnerable to DoS through its HandleRegistrationComplete function Moderate
CVE-2026-4531 was published for github.com/free5gc/amf (Go) Mar 22, 2026
Netmaker Vulnerable to Denial of Service via Server Shutdown Endpoint High
CVE-2026-29771 was published for github.com/gravitl/netmaker (Go) Mar 4, 2026
m4dn355 Credited to m4dn355
OpenClaw: Unauthorized Telegram Senders Trigger Media Download and Disk Write Before Access Check Moderate
GHSA-h656-5vcf-cm23 was published for openclaw (npm) Mar 3, 2026
v8hid Credited to v8hid
Duplicate Advisory: Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence Low
GHSA-fg6r-xgp8-x64r was published for openbabel (pip) Mar 2, 2026 withdrawn
PSI Probe: Broken access control can lead to DoS Low
CVE-2026-3269 was published for com.github.psi-probe:psi-probe-core (Maven) Feb 27, 2026
LIEF is vulnerable to segmentation fault Low
CVE-2025-15504 was published for lief (pip) Jan 10, 2026
Jenkins has a Denial of service vulnerability in HTTP-based CLI High
CVE-2025-67635 was published for org.jenkins-ci.main:cli (Maven) Dec 10, 2025
caverav Credited to caverav
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release Low
CVE-2025-61795 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Oct 27, 2025
tkwilli94 Credited to tkwilli94
Duplicate Advisory: Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read) Low
GHSA-7x26-54jj-cvhr was published for openbabel (pip) Sep 26, 2025 withdrawn
ProTip! Advisories are also available from the GraphQL API