GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,535
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,515
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
101 advisories
Filter by severity
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
Moderate
CVE-2026-71310
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Moderate
CVE-2026-52857
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
Moderate
CVE-2026-54332
was published
for
github.com/gopacket/gopacket
(Go)
Jul 28, 2026
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
Moderate
CVE-2026-54345
was published
for
github.com/gopacket/gopacket
(Go)
Jul 28, 2026
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
Moderate
CVE-2026-57497
was published
for
github.com/quic-go/webtransport-go
(Go)
Jul 24, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Moderate
CVE-2026-55497
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
Moderate
CVE-2026-42931
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
Moderate
CVE-2026-59763
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS
Moderate
CVE-2026-54247
was published
for
github.com/zalando/skipper
(Go)
Jul 17, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions
Moderate
CVE-2026-50018
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Jul 14, 2026
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
Moderate
CVE-2026-55434
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
Moderate
CVE-2026-55078
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
Moderate
CVE-2026-48824
was published
for
github.com/axllent/mailpit
(Go)
Jul 1, 2026
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality
Moderate
CVE-2026-49835
was published
for
github.com/sigstore/timestamp-authority
(Go)
Jun 30, 2026
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
Moderate
CVE-2026-53522
was published
for
github.com/nezhahq/nezha
(Go)
Jun 26, 2026
opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent
Moderate
CVE-2026-48496
was published
for
go.opentelemetry.io/ebpf-profiler
(Go)
Jun 23, 2026
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
Moderate
CVE-2026-40898
was published
for
github.com/quic-go/quic-go
(Go)
Jun 3, 2026
OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens
Moderate
CVE-2026-46405
was published
for
github.com/openbao/openbao
(Go)
May 28, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
Moderate
CVE-2026-45712
was published
for
github.com/axllent/mailpit
(Go)
May 19, 2026
OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals
Moderate
CVE-2026-45682
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
Mattermost doesn't limit the size of the request body on the start meeting API endpoint
Moderate
CVE-2026-2325
was published
for
github.com/mattermost/mattermost-plugin-msteams-meetings
(Go)
May 18, 2026
Volcano's webhook server vulnerable to OOM due to unbounded HTTP request body size
Moderate
CVE-2026-44247
was published
for
volcano.sh/volcano
(Go)
May 8, 2026
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
Moderate
GHSA-pj6q-4vq4-r8cg
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
Incus is affected by unbounded binary import disk exhaustion
Moderate
CVE-2026-41685
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
May 4, 2026
Incus has Unbounded YAML Metadata Decode via Parsing
Moderate
CVE-2026-41648
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
May 4, 2026
ProTip!
Advisories are also available from the
GraphQL API