GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,533
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
408 advisories
Filter by severity
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
High
CVE-2026-53752
was published
for
org.docx4j:docx4j-core
(Maven)
Aug 17, 2026
atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard
High
GHSA-j659-8xh6-5pq5
was published
for
atomic-agents-stack
(pip)
Aug 17, 2026
vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
High
GHSA-v836-6xw4-9cx3
was published
for
vm2
(npm)
Aug 17, 2026
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
High
CVE-2026-47683
was published
for
vm2
(npm)
Aug 17, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
High
CVE-2026-64868
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
Grav: Unauthenticated denial of service via unbounded image derivative dimensions
High
CVE-2026-53653
was published
for
getgrav/grav
(Composer)
Aug 14, 2026
ldap3_proto has LDAP Filter stack exhaustion
High
GHSA-qcxq-75wr-5cm8
was published
for
ldap3_proto
(Rust)
May 6, 2026
pyasn1 has a DoS vulnerability in decoder
High
CVE-2026-23490
was published
for
pyasn1
(pip)
Jan 16, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries
High
GHSA-fp43-vj7g-pg92
was published
for
org.omnifaces:omnifaces
(Maven)
Jul 24, 2026
Micrometer gRPC server instrumentation DoS
High
CVE-2026-40983
was published
for
io.micrometer:micrometer-core
(Maven)
Jun 9, 2026
Micrometer HTTP server instrumentations DoS
High
CVE-2026-40984
was published
for
io.micrometer:micrometer-core
(Maven)
Jun 9, 2026
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
High
CVE-2026-73500
was published
for
go.etcd.io/etcd/v3
(Go)
Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
High
CVE-2026-73493
was published
for
org.http4s:http4s-blaze-server_2.12
(Maven)
Jul 24, 2026
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys
High
CVE-2026-41716
was published
for
org.springframework.data:spring-data-commons
(Maven)
Jun 10, 2026
Gophish contains a denial of service vulnerability
High
CVE-2026-39904
was published
for
github.com/gophish/gophish
(Go)
Jun 22, 2026
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
High
CVE-2026-71321
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
High
CVE-2026-71314
was published
for
nuxt
(npm)
Aug 5, 2026
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
High
CVE-2026-48748
was published
for
io.netty:netty-codec-http3
(Maven)
Jun 15, 2026
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
High
GHSA-r7wm-3cxj-wff9
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Jul 21, 2026
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
High
CVE-2026-69152
was published
for
brace-expansion
(npm)
Aug 3, 2026
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
High
CVE-2026-14257
was published
for
brace-expansion
(npm)
Jul 24, 2026
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
High
CVE-2026-67432
was published
for
mcp
(RubyGems)
Jul 30, 2026
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
High
CVE-2026-67437
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
Spring HATEOAS heap exhaustion through unbounded internal caching
High
CVE-2026-41007
was published
for
org.springframework.hateoas:spring-hateoas
(Maven)
Jun 9, 2026
gun has an Uncontrolled Resource Consumption vulnerability
High
CVE-2026-43973
was published
for
gun
(Erlang)
Jun 8, 2026
ProTip!
Advisories are also available from the
GraphQL API