Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

70 advisories

Loading
vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass High
GHSA-v836-6xw4-9cx3 was published for vm2 (npm) Aug 17, 2026
Kr1shna4garwal Credited to Kr1shna4garwal
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike High
CVE-2026-47683 was published for vm2 (npm) Aug 17, 2026
fg0x0 Credited to fg0x0 and Kr1shna4garwal Kr1shna4garwal Kr1shna4garwal
dinhvaren Credited to dinhvaren
manop55555 Credited to manop55555
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation High
CVE-2026-69152 was published for brace-expansion (npm) Aug 3, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding High
CVE-2026-54609 was published for com.quietterminal:qti-neon (Maven) Jul 28, 2026
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash High
CVE-2026-14257 was published for brace-expansion (npm) Jul 24, 2026
bnbdr Credited to bnbdr and G-Rath G-Rath G-Rath
react-server-dom: Denial of Service in Server Functions High
CVE-2026-44907 was published for react-server-dom-parcel (npm) Jul 24, 2026
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce High
CVE-2026-55575 was published for liquidjs (npm) Jul 24, 2026
offset Credited to offset
dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS High
CVE-2026-50272 was published for dd-trace (npm) Jul 15, 2026
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays High
CVE-2026-49866 was published for @libp2p/gossipsub (npm) Jul 10, 2026
tahaafarooq Credited to tahaafarooq
undici WebSocket client vulnerable to denial of service via fragment count bypass High
CVE-2026-12151 was published for undici (npm) Jun 19, 2026
lpinca Credited to lpinca, Nadav0077, and UlisesGascon Nadav0077 Nadav0077
UlisesGascon UlisesGascon
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass High
CVE-2026-9675 was published for undici (npm) Jun 18, 2026
mauriceng98 Credited to mauriceng98, Str1ckl4nd, mcollina, and UlisesGascon Str1ckl4nd Str1ckl4nd
mcollina mcollina UlisesGascon UlisesGascon
ws: Memory exhaustion DoS from tiny fragments and data chunks High
CVE-2026-48779 was published for ws (npm) Jun 15, 2026
Nadav0077 Credited to Nadav0077
React Router vulnerable to Denial of Service via reflected user input in single-fetch High
CVE-2026-34077 was published for react-router (npm) Jun 4, 2026
Oceandust Credited to Oceandust
Allocation of Resources Without Limits or Throttling in Axios High
CVE-2026-44488 was published for axios (npm) Jun 4, 2026
asadeddin Credited to asadeddin
Svelte devalue: DoS via sparse array deserialization High
CVE-2026-42570 was published for devalue (npm) May 14, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github, dummdidumm, and kq5y dummdidumm dummdidumm
kq5y kq5y
@vitejs/plugin-rsc has a Denial of Service Vulnerability in React Server Components High
GHSA-w94c-4vhp-22gx was published for @vitejs/plugin-rsc (npm) May 11, 2026
Next.js Vulnerable to Denial of Service with Server Components High
GHSA-8h8q-6873-q5fj was published for next (npm) May 11, 2026
Facebook React has a Denial of Service Vulnerability in React Server Components High
CVE-2026-23870 was published for react-server-dom-parcel (npm) May 11, 2026
@fastify/accepts-serializer Vulnerable to Denial of Service via Unbounded Accept Header Cache Growth High
CVE-2026-7768 was published for @fastify/accepts-serializer (npm) May 8, 2026
yuki-matsuhashi Credited to yuki-matsuhashi and UlisesGascon UlisesGascon UlisesGascon
koDove Credited to koDove
thesmartshadow Credited to thesmartshadow
ProTip! Advisories are also available from the GraphQL API