GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
104 advisories
Filter by severity
ffuf denial of service (OOM) via HTTP response decompression bomb
High
CVE-2026-73232
was published
for
github.com/ffuf/ffuf
(Go)
Sep 3, 2026
Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits
Moderate
CVE-2026-61690
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent...
Moderate
Unreviewed
CVE-2026-78594
was published
Sep 2, 2026
Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service...
Moderate
Unreviewed
CVE-2026-72628
was published
Sep 1, 2026
MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS
Moderate
GHSA-rgwj-5xj2-c3m3
was published
for
mysql2
(npm)
Aug 31, 2026
pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the...
High
Unreviewed
CVE-2026-82864
was published
Aug 31, 2026
The UnZipTransformer does not limit decompressed entry size or entry count when processing...
Moderate
Unreviewed
CVE-2026-59274
was published
Aug 27, 2026
LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write....
High
Unreviewed
CVE-2026-80189
was published
Aug 26, 2026
http4s has HTTP/2 Denial of Service with Ember Backend
High
CVE-2026-54556
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Aug 26, 2026
gRPC Erlang package has unbounded gzip decompression (decompression bomb)
High
CVE-2026-53430
was published
for
grpc
(Erlang)
Aug 25, 2026
exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory...
High
Unreviewed
CVE-2026-78206
was published
Aug 24, 2026
Tanium addressed a compression bomb vulnerability in Threat Response.
Low
Unreviewed
CVE-2026-75476
was published
Aug 19, 2026
Tanium addressed a compression bomb vulnerability in Findings.
Low
Unreviewed
CVE-2026-11617
was published
Aug 19, 2026
Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting...
High
Unreviewed
CVE-2026-19671
was published
Aug 18, 2026
Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when...
Moderate
Unreviewed
CVE-2026-18929
was published
Aug 18, 2026
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
High
CVE-2026-53659
was published
for
org.http4k:http4k-core
(Maven)
Aug 17, 2026
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the...
Moderate
Unreviewed
CVE-2026-75047
was published
Aug 17, 2026
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22...
Moderate
Unreviewed
CVE-2026-14298
was published
Aug 13, 2026
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API...
High
Unreviewed
CVE-2026-68981
was published
Aug 3, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
CVE-2026-49755
was published
for
req
(Erlang)
Jul 29, 2026
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4...
Moderate
Unreviewed
CVE-2026-10819
was published
Jul 27, 2026
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C...
High
Unreviewed
CVE-2026-48586
was published
Jul 27, 2026
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift...
High
Unreviewed
CVE-2026-49158
was published
Jul 27, 2026
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
High
CVE-2026-41608
was published
for
thrift
(pip)
Jul 27, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Moderate
CVE-2026-55497
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API