Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

104 advisories

Loading
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files Moderate
GHSA-xg43-5579-qw6v was published for adawolfa/isdoc (Composer) Jul 15, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload High
CVE-2026-56755 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion High
CVE-2026-59932 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling High
CVE-2026-59939 was published for httplib2 (pip) Jul 24, 2026
mauriceng98 Credited to mauriceng98
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server Moderate
CVE-2026-55497 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
riodrwn Credited to riodrwn
carlosfunk Credited to carlosfunk and oscerd oscerd oscerd
Req vulnerable to unbounded archive/compression extraction triggered by response content-type High
CVE-2026-49755 was published for req (Erlang) Jul 29, 2026
PJUllrich Credited to PJUllrich and maennchen maennchen maennchen
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS High
CVE-2026-53659 was published for org.http4k:http4k-core (Maven) Aug 17, 2026
Tanium addressed a compression bomb vulnerability in Findings. Low Unreviewed
CVE-2026-11617 was published Aug 19, 2026
Tanium addressed a compression bomb vulnerability in Threat Response. Low Unreviewed
CVE-2026-75476 was published Aug 19, 2026
gRPC Erlang package has unbounded gzip decompression (decompression bomb) High
CVE-2026-53430 was published for grpc (Erlang) Aug 25, 2026
PJUllrich Credited to PJUllrich and polvalente polvalente polvalente
http4s has HTTP/2 Denial of Service with Ember Backend High
CVE-2026-54556 was published for org.http4s:http4s-ember-core_2.12 (Maven) Aug 26, 2026
reardonj Credited to reardonj and rossabaker rossabaker rossabaker
MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS Moderate
GHSA-rgwj-5xj2-c3m3 was published for mysql2 (npm) Aug 31, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
ProTip! Advisories are also available from the GraphQL API