GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
34 advisories
Filter by severity
ffuf denial of service (OOM) via HTTP response decompression bomb
High
CVE-2026-73232
was published
for
github.com/ffuf/ffuf
(Go)
Sep 3, 2026
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
High
CVE-2026-41608
was published
for
thrift
(pip)
Jul 27, 2026
http4s has HTTP/2 Denial of Service with Ember Backend
High
CVE-2026-54556
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Aug 26, 2026
gRPC Erlang package has unbounded gzip decompression (decompression bomb)
High
CVE-2026-53430
was published
for
grpc
(Erlang)
Aug 25, 2026
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
High
CVE-2026-59939
was published
for
httplib2
(pip)
Jul 24, 2026
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
High
CVE-2026-53659
was published
for
org.http4k:http4k-core
(Maven)
Aug 17, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
CVE-2026-49755
was published
for
req
(Erlang)
Jul 29, 2026
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
High
CVE-2026-59932
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
High
CVE-2026-56755
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Tesla has decompression bomb on response body
High
CVE-2026-48594
was published
for
tesla
(Erlang)
Jul 10, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
High
CVE-2026-44160
was published
for
fluentd
(RubyGems)
Jun 26, 2026
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
High
CVE-2026-48502
was published
for
MessagePack
(NuGet)
Jun 25, 2026
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
High
CVE-2026-49855
was published
for
tornado
(pip)
Jun 15, 2026
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
High
CVE-2026-44432
was published
for
urllib3
(pip)
May 11, 2026
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload
High
CVE-2026-44697
was published
for
github.com/klever-io/klever-go
(Go)
May 13, 2026
cowlib: Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
High
CVE-2026-43970
was published
for
cowlib
(Erlang)
May 13, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
CVE-2026-40036
was published
for
dfir-unfurl
(pip)
Jan 29, 2026
Duplicate Advisory: Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
GHSA-c3f2-qg8v-25q2
was published
for
dfir-unfurl
(pip)
Apr 9, 2026
•
withdrawn
Scrapy decompression bomb vulnerability
High
CVE-2024-3572
was published
for
scrapy
(pip)
Feb 16, 2024
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
High
CVE-2026-1526
was published
for
undici
(npm)
Mar 13, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder
High
GHSA-2phg-qgmm-r638
was published
for
github.com/BishopFox/sliver
(Go)
Feb 25, 2026
Apollo Router's Compressed Payloads do not respect HTTP Payload Limits
High
CVE-2024-28101
was published
for
apollo-router
(Rust)
Mar 6, 2024
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
High
CVE-2026-21441
was published
for
urllib3
(pip)
Jan 7, 2026
GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS
High
CVE-2026-22870
was published
for
guarddog
(pip)
Jan 13, 2026
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
High
CVE-2025-69223
was published
for
aiohttp
(pip)
Jan 5, 2026
ProTip!
Advisories are also available from the
GraphQL API