Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

408 advisories

Loading
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service High
CVE-2026-53752 was published for org.docx4j:docx4j-core (Maven) Aug 17, 2026
vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass High
GHSA-v836-6xw4-9cx3 was published for vm2 (npm) Aug 17, 2026
Kr1shna4garwal Credited to Kr1shna4garwal
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike High
CVE-2026-47683 was published for vm2 (npm) Aug 17, 2026
fg0x0 Credited to fg0x0 and Kr1shna4garwal Kr1shna4garwal Kr1shna4garwal
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging High
CVE-2026-64868 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
passer12 Credited to passer12
Grav: Unauthenticated denial of service via unbounded image derivative dimensions High
CVE-2026-53653 was published for getgrav/grav (Composer) Aug 14, 2026
iliaal Credited to iliaal
ldap3_proto has LDAP Filter stack exhaustion High
GHSA-qcxq-75wr-5cm8 was published for ldap3_proto (Rust) May 6, 2026
mbarbero Credited to mbarbero and micolous micolous micolous
pyasn1 has a DoS vulnerability in decoder High
CVE-2026-23490 was published for pyasn1 (pip) Jan 16, 2026
tsigouris007 Credited to tsigouris007
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
Micrometer gRPC server instrumentation DoS High
CVE-2026-40983 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Micrometer HTTP server instrumentations DoS High
CVE-2026-40984 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline High
CVE-2026-73500 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server High
CVE-2026-73493 was published for org.http4s:http4s-blaze-server_2.12 (Maven) Jul 24, 2026
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys High
CVE-2026-41716 was published for org.springframework.data:spring-data-commons (Maven) Jun 10, 2026
Gophish contains a denial of service vulnerability High
CVE-2026-39904 was published for github.com/gophish/gophish (Go) Jun 22, 2026
ashikmd7 Credited to ashikmd7
dinhvaren Credited to dinhvaren
manop55555 Credited to manop55555
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion High
CVE-2026-48748 was published for io.netty:netty-codec-http3 (Maven) Jun 15, 2026
violetagg Credited to violetagg and julianladisch julianladisch julianladisch
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) High
GHSA-r7wm-3cxj-wff9 was published for com.fasterxml.jackson.core:jackson-core (Maven) Jul 21, 2026
tonghuaroot Credited to tonghuaroot, pjfanning, and cowtowncoder pjfanning pjfanning
cowtowncoder cowtowncoder
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation High
CVE-2026-69152 was published for brace-expansion (npm) Aug 3, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash High
CVE-2026-14257 was published for brace-expansion (npm) Jul 24, 2026
bnbdr Credited to bnbdr and G-Rath G-Rath G-Rath
hewei-gikaku Credited to hewei-gikaku
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) High
CVE-2026-67437 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
knight-yagami Credited to knight-yagami
Spring HATEOAS heap exhaustion through unbounded internal caching High
CVE-2026-41007 was published for org.springframework.hateoas:spring-hateoas (Maven) Jun 9, 2026
gun has an Uncontrolled Resource Consumption vulnerability High
CVE-2026-43973 was published for gun (Erlang) Jun 8, 2026
ProTip! Advisories are also available from the GraphQL API