Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,292 advisories

Loading
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS High
CVE-2026-53659 was published for org.http4k:http4k-core (Maven) Aug 17, 2026
http4k: `DigestAuthProvider.verify` did not bind to request URI High
CVE-2026-54148 was published for org.http4k:http4k-security-digest (Maven) Aug 17, 2026
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service High
CVE-2026-53752 was published for org.docx4j:docx4j-core (Maven) Aug 17, 2026
Netty: Memory Exhaustion in SctpMessageCompletionHandler High
CVE-2026-59902 was published for io.netty:netty-transport-sctp (Maven) Aug 17, 2026
violetagg Credited to violetagg
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets" High
CVE-2026-55153 was published for com.mchange:mchange-commons-java (Maven) Aug 14, 2026
4ra1n Credited to 4ra1n, unam4, and vmulas unam4 unam4
vmulas vmulas
OpenAM Insecure SSO Cookie Initialization High
CVE-2026-53660 was published for org.openidentityplatform.openam:openam-core (Maven) Aug 14, 2026
wodzen Credited to wodzen
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing High
CVE-2026-2332 was published for org.eclipse.jetty:jetty-http (Maven) Apr 14, 2026
xclow3n Credited to xclow3n, jhy, tlarionova-max, and ryanmurf jhy jhy
tlarionova-max tlarionova-max ryanmurf ryanmurf
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) High
CVE-2026-54513 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
omkhar Credited to omkhar
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK High
CVE-2026-54428 was published for org.apache.httpcomponents.core5:httpcore5-h2 (Maven) Jul 1, 2026
Lueton Credited to Lueton
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation High
CVE-2026-53435 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Netty has Insufficient Bailiwick Validation for NS Records High
CVE-2026-47691 was published for io.netty:netty-resolver-dns (Maven) Jun 8, 2026
violetagg Credited to violetagg
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion High
CVE-2026-48059 was published for io.netty:netty-codec-haproxy (Maven) Jun 11, 2026
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records High
CVE-2026-45674 was published for io.netty:netty-resolver-dns (Maven) Jun 8, 2026
violetagg Credited to violetagg
Micrometer gRPC server instrumentation DoS High
CVE-2026-40983 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Micrometer HTTP server instrumentations DoS High
CVE-2026-40984 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Quarkus has Authentication/Authorization bypasses High
CVE-2026-39852 was published for io.quarkus:quarkus-vertx-http (Maven) May 4, 2026
p- Credited to p-
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion High
CVE-2026-73507 was published for io.netty:netty-codec-xml (Maven) Jul 24, 2026
violetagg Credited to violetagg
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser High
CVE-2026-73494 was published for org.http4s:blaze-http_2.13 (Maven) Jul 24, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass) High
CVE-2026-73495 was published for org.http4s:blaze-http_2.12 (Maven) Jul 24, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server High
CVE-2026-73493 was published for org.http4s:http4s-blaze-server_2.12 (Maven) Jul 24, 2026
Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service High
CVE-2026-54399 was published for org.apache.httpcomponents.core5:httpcore5 (Maven) Jul 1, 2026
tikri Credited to tikri
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File High
CVE-2026-34487 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Apr 9, 2026
aruneko Credited to aruneko and antonbombov antonbombov antonbombov
Apache cxf-core: No restriction on attachment headers per message High
CVE-2026-50645 was published for org.apache.cxf:cxf-core (Maven) Jun 12, 2026
julianladisch Credited to julianladisch, coheigea, and udengaardandersent-ELS coheigea coheigea
udengaardandersent-ELS udengaardandersent-ELS
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests High
CVE-2026-41729 was published for org.springframework.data:spring-data-rest-core (Maven) Jun 10, 2026
ProTip! Advisories are also available from the GraphQL API