GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,533
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,292 advisories
Filter by severity
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
High
CVE-2026-53659
was published
for
org.http4k:http4k-core
(Maven)
Aug 17, 2026
http4k: `DigestAuthProvider.verify` did not bind to request URI
High
CVE-2026-54148
was published
for
org.http4k:http4k-security-digest
(Maven)
Aug 17, 2026
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
High
CVE-2026-53752
was published
for
org.docx4j:docx4j-core
(Maven)
Aug 17, 2026
Netty: Memory Exhaustion in SctpMessageCompletionHandler
High
CVE-2026-59902
was published
for
io.netty:netty-transport-sctp
(Maven)
Aug 17, 2026
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
High
CVE-2026-55153
was published
for
com.mchange:mchange-commons-java
(Maven)
Aug 14, 2026
OpenAM Insecure SSO Cookie Initialization
High
CVE-2026-53660
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Aug 14, 2026
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
High
CVE-2026-2332
was published
for
org.eclipse.jetty:jetty-http
(Maven)
Apr 14, 2026
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
High
CVE-2026-54513
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
High
CVE-2026-54428
was published
for
org.apache.httpcomponents.core5:httpcore5-h2
(Maven)
Jul 1, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries
High
GHSA-fp43-vj7g-pg92
was published
for
org.omnifaces:omnifaces
(Maven)
Jul 24, 2026
Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation
High
CVE-2026-53435
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Netty has Insufficient Bailiwick Validation for NS Records
High
CVE-2026-47691
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
High
CVE-2026-48059
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jun 11, 2026
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
High
CVE-2026-45674
was published
for
io.netty:netty-resolver-dns
(Maven)
Jun 8, 2026
Micrometer gRPC server instrumentation DoS
High
CVE-2026-40983
was published
for
io.micrometer:micrometer-core
(Maven)
Jun 9, 2026
Micrometer HTTP server instrumentations DoS
High
CVE-2026-40984
was published
for
io.micrometer:micrometer-core
(Maven)
Jun 9, 2026
Quarkus has Authentication/Authorization bypasses
High
CVE-2026-39852
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
May 4, 2026
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
High
CVE-2026-73507
was published
for
io.netty:netty-codec-xml
(Maven)
Jul 24, 2026
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
High
CVE-2026-73494
was published
for
org.http4s:blaze-http_2.13
(Maven)
Jul 24, 2026
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
High
CVE-2026-73495
was published
for
org.http4s:blaze-http_2.12
(Maven)
Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
High
CVE-2026-73493
was published
for
org.http4s:http4s-blaze-server_2.12
(Maven)
Jul 24, 2026
Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service
High
CVE-2026-54399
was published
for
org.apache.httpcomponents.core5:httpcore5
(Maven)
Jul 1, 2026
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
High
CVE-2026-34487
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
Apache cxf-core: No restriction on attachment headers per message
High
CVE-2026-50645
was published
for
org.apache.cxf:cxf-core
(Maven)
Jun 12, 2026
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests
High
CVE-2026-41729
was published
for
org.springframework.data:spring-data-rest-core
(Maven)
Jun 10, 2026
ProTip!
Advisories are also available from the
GraphQL API