GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
26 advisories
Filter by severity
Phoenix: Unbounded channel joins per transport enables DoS over few connections
High
CVE-2026-56811
was published
for
phoenix
(Erlang)
Sep 3, 2026
gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
High
CVE-2026-48854
was published
for
grpc
(Erlang)
Aug 25, 2026
gRPC Erlang package's path bindings are overridable by query string and request body
High
CVE-2026-48599
was published
for
grpc
(Erlang)
Aug 25, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
CVE-2026-49755
was published
for
req
(Erlang)
Jul 29, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
CVE-2026-48597
was published
for
tesla
(Erlang)
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
CVE-2026-48595
was published
for
tesla
(Erlang)
Jul 10, 2026
Tesla has decompression bomb on response body
High
CVE-2026-48594
was published
for
tesla
(Erlang)
Jul 10, 2026
mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
High
CVE-2026-48862
was published
for
mint
(Erlang)
Jul 9, 2026
mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)
High
CVE-2026-49754
was published
for
mint
(Erlang)
Jul 9, 2026
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
High
CVE-2026-47074
was published
for
ex_aws_sns
(Erlang)
Jun 26, 2026
Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes
High
CVE-2026-47067
was published
for
hackney
(Erlang)
Jun 26, 2026
Hackney has unbounded buffer accumulation in WebSocket
High
CVE-2026-47073
was published
for
hackney
(Erlang)
Jun 26, 2026
Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
High
CVE-2026-47077
was published
for
hackney
(Erlang)
Jun 26, 2026
Hackney: `ssl:connect/2` post-handshake upgrade has no timeout
High
CVE-2026-47071
was published
for
hackney
(Erlang)
Jun 26, 2026
Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry
High
CVE-2026-47066
was published
for
hackney
(Erlang)
Jun 26, 2026
PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)
High
CVE-2026-8469
was published
for
phoenix_storybook
(Erlang)
Jun 9, 2026
Plug: Unbounded buffer accumulation in multipart header parsing causes denial of service
High
CVE-2026-8468
was published
for
plug
(Erlang)
May 20, 2026
Bandit: Unauthenticated DoS via chunked request trailers in Bandit HTTP/1 decoder
High
CVE-2026-39806
was published
for
bandit
(Erlang)
May 19, 2026
Bandit: Unauthenticated one-shot DoS via `Transfer-Encoding: chunked`
High
CVE-2026-39803
was published
for
bandit
(Erlang)
May 19, 2026
Bandit Buffers Unbounded WebSocket Continuation Frames, Allowing Unauthenticated Memory Exhaustion
High
CVE-2026-42786
was published
for
bandit
(Erlang)
May 7, 2026
Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame
High
CVE-2026-39804
was published
for
bandit
(Erlang)
May 7, 2026
Ash has authorization bypass when bypass policy condition evaluates to true
High
CVE-2025-48044
was published
for
ash
(Erlang)
Oct 17, 2025
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies
High
CVE-2025-48043
was published
for
ash
(Erlang)
Oct 13, 2025
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
High
CVE-2025-48042
was published
for
ash
(Erlang)
Sep 15, 2025
Phoenix before 1.6.14 mishandles check_origin wildcarding
High
CVE-2022-42975
was published
for
phoenix
(Erlang)
Oct 17, 2022
ProTip!
Advisories are also available from the
GraphQL API