Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34 advisories

Loading
ffuf denial of service (OOM) via HTTP response decompression bomb High
CVE-2026-73232 was published for github.com/ffuf/ffuf (Go) Sep 3, 2026
Tricta Credited to Tricta
carlosfunk Credited to carlosfunk and oscerd oscerd oscerd
http4s has HTTP/2 Denial of Service with Ember Backend High
CVE-2026-54556 was published for org.http4s:http4s-ember-core_2.12 (Maven) Aug 26, 2026
reardonj Credited to reardonj and rossabaker rossabaker rossabaker
gRPC Erlang package has unbounded gzip decompression (decompression bomb) High
CVE-2026-53430 was published for grpc (Erlang) Aug 25, 2026
PJUllrich Credited to PJUllrich and polvalente polvalente polvalente
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling High
CVE-2026-59939 was published for httplib2 (pip) Jul 24, 2026
mauriceng98 Credited to mauriceng98
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS High
CVE-2026-53659 was published for org.http4k:http4k-core (Maven) Aug 17, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type High
CVE-2026-49755 was published for req (Erlang) Jul 29, 2026
PJUllrich Credited to PJUllrich and maennchen maennchen maennchen
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion High
CVE-2026-59932 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload High
CVE-2026-56755 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Tesla has decompression bomb on response body High
CVE-2026-48594 was published for tesla (Erlang) Jul 10, 2026
PJUllrich Credited to PJUllrich, yordis, and maennchen yordis yordis
maennchen maennchen
everping Credited to everping
AArnott Credited to AArnott
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) High
CVE-2026-49855 was published for tornado (pip) Jun 15, 2026
yuui25 Credited to yuui25
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API High
CVE-2026-44432 was published for urllib3 (pip) May 11, 2026
kimkou2024 Credited to kimkou2024, Cycloctane, illia-v, and pquentin Cycloctane Cycloctane
illia-v illia-v pquentin pquentin
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload High
CVE-2026-44697 was published for github.com/klever-io/klever-go (Go) May 13, 2026
fbsobreira Credited to fbsobreira
cowlib: Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame High
CVE-2026-43970 was published for cowlib (Erlang) May 13, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS High
CVE-2026-40036 was published for dfir-unfurl (pip) Jan 29, 2026
mobasi-team Credited to mobasi-team
Duplicate Advisory: Unfurl's unbounded zlib decompression allows decompression bomb DoS High
GHSA-c3f2-qg8v-25q2 was published for dfir-unfurl (pip) Apr 9, 2026 withdrawn
Scrapy decompression bomb vulnerability High
CVE-2024-3572 was published for scrapy (pip) Feb 16, 2024
dmandefy Credited to dmandefy
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression High
CVE-2026-1526 was published for undici (npm) Mar 13, 2026
HO-9 Credited to HO-9, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder High
GHSA-2phg-qgmm-r638 was published for github.com/BishopFox/sliver (Go) Feb 25, 2026
Cycloctane Credited to Cycloctane
Apollo Router's Compressed Payloads do not respect HTTP Payload Limits High
CVE-2024-28101 was published for apollo-router (Rust) Mar 6, 2024
IvanGoncharov Credited to IvanGoncharov, Geal, peakematt, and sunnypatell Geal Geal
peakematt peakematt sunnypatell sunnypatell
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) High
CVE-2026-21441 was published for urllib3 (pip) Jan 7, 2026
D47A Credited to D47A, illia-v, pquentin, and sethmlarson illia-v illia-v
pquentin pquentin sethmlarson sethmlarson
GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS High
CVE-2026-22870 was published for guarddog (pip) Jan 13, 2026
dwBruijn Credited to dwBruijn
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb High
CVE-2025-69223 was published for aiohttp (pip) Jan 5, 2026
charleswhchan Credited to charleswhchan and bdraco bdraco bdraco
ProTip! Advisories are also available from the GraphQL API