Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

194 advisories

Loading
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM Moderate
CVE-2026-52857 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
WilliamVenner Credited to WilliamVenner
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode High
CVE-2026-54638 was published for github.com/gotd/td (Go) Jul 28, 2026
ayman148754-cloud Credited to ayman148754-cloud
pypdf: Possible large memory usage for wrong image dimensions Moderate
CVE-2026-59938 was published for pypdf (pip) Jul 23, 2026
MR-SS Credited to MR-SS and stefan6419846 stefan6419846 stefan6419846
Brubbish Credited to Brubbish
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()` High
CVE-2026-55380 was published for pillow (pip) Jul 20, 2026
x-forwarded-sudo Credited to x-forwarded-sudo
x-forwarded-sudo Credited to x-forwarded-sudo
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()` High
CVE-2026-54060 was published for pillow (pip) Jul 20, 2026
dino320 Credited to dino320
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header Moderate
CVE-2026-53717 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
zhaohuabing Credited to zhaohuabing
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit Moderate
CVE-2026-53716 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
zhaohuabing Credited to zhaohuabing
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser High
CVE-2026-54448 was published for github.com/aquasecurity/trivy (Go) Jul 14, 2026
adm-zip: Crafted ZIP file triggers 4GB memory allocation High
CVE-2026-39244 was published for adm-zip (npm) Jul 10, 2026
julianladisch Credited to julianladisch
Tanium addressed a denial of service vulnerability in Tanium Server. High Unreviewed
CVE-2026-15053 was published Jul 8, 2026
ProTip! Advisories are also available from the GraphQL API