Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

101 advisories

Loading
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory Moderate
CVE-2026-71310 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM Moderate
CVE-2026-52857 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
WilliamVenner Credited to WilliamVenner
tonghuaroot Credited to tonghuaroot and mosajjal mosajjal mosajjal
tonghuaroot Credited to tonghuaroot and mosajjal mosajjal mosajjal
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules Moderate
CVE-2026-57497 was published for github.com/quic-go/webtransport-go (Go) Jul 24, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server Moderate
CVE-2026-55497 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
riodrwn Credited to riodrwn
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint Moderate
CVE-2026-42931 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Tricta Credited to Tricta
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads Moderate
CVE-2026-59763 was published for code.gitea.io/gitea (Go) Jul 21, 2026
kkkh1 Credited to kkkh1
Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS Moderate
CVE-2026-54247 was published for github.com/zalando/skipper (Go) Jul 17, 2026
alcls01111 Credited to alcls01111
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions Moderate
CVE-2026-50018 was published for github.com/SpectoLabs/hoverfly (Go) Jul 14, 2026
Kr1shna4garwal Credited to Kr1shna4garwal
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints Moderate
CVE-2026-55434 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service Moderate
CVE-2026-55078 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality Moderate
CVE-2026-49835 was published for github.com/sigstore/timestamp-authority (Go) Jun 30, 2026
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS Moderate
CVE-2026-53522 was published for github.com/nezhahq/nezha (Go) Jun 26, 2026
alcls01111 Credited to alcls01111
opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent Moderate
CVE-2026-48496 was published for go.opentelemetry.io/ebpf-profiler (Go) Jun 23, 2026
alban Credited to alban, christos68k, and florianl christos68k christos68k
florianl florianl
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion Moderate
CVE-2026-40898 was published for github.com/quic-go/quic-go (Go) Jun 3, 2026
OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens Moderate
CVE-2026-46405 was published for github.com/openbao/openbao (Go) May 28, 2026
KadirArslan Credited to KadirArslan
OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals Moderate
CVE-2026-45682 was published for go.opentelemetry.io/obi (Go) May 18, 2026
MrAlias Credited to MrAlias and grcevski grcevski grcevski
Mattermost doesn't limit the size of the request body on the start meeting API endpoint Moderate
CVE-2026-2325 was published for github.com/mattermost/mattermost-plugin-msteams-meetings (Go) May 18, 2026
Volcano's webhook server vulnerable to OOM due to unbounded HTTP request body size Moderate
CVE-2026-44247 was published for volcano.sh/volcano (Go) May 8, 2026
JesseStutler Credited to JesseStutler, bugbunny-research, hzxuzhonghu, and kevin-wangzefeng bugbunny-research bugbunny-research
hzxuzhonghu hzxuzhonghu kevin-wangzefeng kevin-wangzefeng
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count Moderate
GHSA-pj6q-4vq4-r8cg was published for github.com/lin-snow/Ech0 (Go) May 7, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
Incus is affected by unbounded binary import disk exhaustion Moderate
CVE-2026-41685 was published for github.com/lxc/incus/v6/cmd/incusd (Go) May 4, 2026
stamparm Credited to stamparm and stgraber stgraber stgraber
Incus has Unbounded YAML Metadata Decode via Parsing Moderate
CVE-2026-41648 was published for github.com/lxc/incus/v6/cmd/incusd (Go) May 4, 2026
raefko Credited to raefko, Ectario, and stgraber Ectario Ectario
stgraber stgraber
ProTip! Advisories are also available from the GraphQL API