GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
39 advisories
Filter by severity
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
High
CVE-2026-77354
was published
for
github.com/getkin/kin-openapi
(Go)
Aug 21, 2026
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
High
CVE-2026-55149
was published
for
github.com/vouch/vouch-proxy
(Go)
Aug 20, 2026
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation
High
CVE-2026-69219
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
High
CVE-2026-71314
was published
for
nuxt
(npm)
Aug 5, 2026
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
High
CVE-2026-54638
was published
for
github.com/gotd/td
(Go)
Jul 28, 2026
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
High
CVE-2026-59204
was published
for
pillow
(pip)
Jul 20, 2026
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
High
CVE-2026-55380
was published
for
pillow
(pip)
Jul 20, 2026
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
High
CVE-2026-55379
was published
for
pillow
(pip)
Jul 20, 2026
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
High
CVE-2026-54060
was published
for
pillow
(pip)
Jul 20, 2026
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
High
CVE-2026-54059
was published
for
pillow
(pip)
Jul 20, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
High
CVE-2026-54448
was published
for
github.com/aquasecurity/trivy
(Go)
Jul 14, 2026
adm-zip: Crafted ZIP file triggers 4GB memory allocation
High
CVE-2026-39244
was published
for
adm-zip
(npm)
Jul 10, 2026
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
High
CVE-2026-48502
was published
for
MessagePack
(NuGet)
Jun 25, 2026
kafka-python vulnerable to denial of service through an unvalidated protocol frame length
High
CVE-2026-10142
was published
for
kafka-python
(pip)
Jun 11, 2026
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation
High
CVE-2026-5740
was published
for
github.com/mattermost/mattermost-server
(Go)
May 26, 2026
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
High
GHSA-mx64-mj3q-7prj
was published
for
github.com/iskorotkov/avro/v2
(Go)
May 18, 2026
rust-zserio has Unbounded Memory Allocation
High
GHSA-fpf5-4jw8-67x8
was published
for
rust-zserio
(Rust)
May 7, 2026
Netty HTTP/3 QPACK literal unbounded allocation
High
CVE-2026-42582
was published
for
io.netty:netty-codec-http3
(Maven)
May 7, 2026
Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowException
High
CVE-2026-44375
was published
for
Nerdbank.MessagePack
(NuGet)
May 6, 2026
Prometheus: Remote read endpoint allows denial of service via crafted snappy payload
High
CVE-2026-42154
was published
for
github.com/prometheus/prometheus
(Go)
May 5, 2026
Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation
High
CVE-2026-42440
was published
for
org.apache.opennlp:opennlp-tools
(Maven)
May 4, 2026
Zserio Runtime: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization
High
CVE-2026-33524
was published
for
io.github.ndsev:zserio-runtime
(Maven)
Apr 24, 2026
russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler
High
CVE-2026-42189
was published
for
russh
(Rust)
Apr 24, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
High
CVE-2026-40303
was published
for
github.com/openziti/zrok
(Go)
Apr 16, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation
High
CVE-2026-25899
was published
for
github.com/gofiber/fiber/v3
(Go)
Feb 24, 2026
ProTip!
Advisories are also available from the
GraphQL API