GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
49 advisories
Filter by severity
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
Moderate
CVE-2026-55407
was published
for
buffa
(Rust)
Aug 28, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Moderate
CVE-2026-52857
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
pypdf: Possible large memory usage for wrong image dimensions
Moderate
CVE-2026-59938
was published
for
pypdf
(pip)
Jul 23, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
Moderate
CVE-2026-53717
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Moderate
CVE-2026-53716
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
Moderate
CVE-2026-55079
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing
Moderate
CVE-2026-54697
was published
for
org.connectbot.sshlib:sshlib
(Maven)
Jun 12, 2026
ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation
Moderate
CVE-2026-54700
was published
for
org.connectbot.sshlib:sshlib
(Maven)
Jun 12, 2026
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
Moderate
CVE-2026-47734
was published
for
dulwich
(pip)
Jun 8, 2026
opentelemetry-go's baggage parsing no longer caps raw header length
Moderate
CVE-2026-41178
was published
for
go.opentelemetry.io/otel/baggage
(Go)
May 28, 2026
Mattermost doesn't validate 7zip archive structure before processing
Moderate
CVE-2026-6340
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
OpAMP client reads unbounded HTTP response bodies
Moderate
CVE-2026-42348
was published
for
OpenTelemetry.OpAmp.Client
(NuGet)
May 5, 2026
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability
Moderate
CVE-2026-43868
was published
for
thrift
(Rust)
May 5, 2026
ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width
Moderate
CVE-2026-42241
was published
for
ParquetSharp
(NuGet)
Apr 24, 2026
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
Moderate
CVE-2026-40894
was published
for
OpenTelemetry.Api
(NuGet)
Apr 23, 2026
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
Moderate
CVE-2026-40891
was published
for
OpenTelemetry.Exporter.OpenTelemetryProtocol
(NuGet)
Apr 23, 2026
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
Moderate
CVE-2026-40182
was published
for
OpenTelemetry.Exporter.OpenTelemetryProtocol
(NuGet)
Apr 23, 2026
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
Moderate
CVE-2026-41314
was published
for
pypdf
(pip)
Apr 16, 2026
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
Moderate
CVE-2026-41312
was published
for
pypdf
(pip)
Apr 16, 2026
Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend
Moderate
CVE-2026-35186
was published
for
wasmtime
(Rust)
Apr 10, 2026
Duplicate Advisory: OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure
Moderate
GHSA-hm63-vwj4-mj2q
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64
Moderate
CVE-2026-34944
was published
for
wasmtime
(Rust)
Apr 9, 2026
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
Moderate
CVE-2026-39882
was published
for
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp
(Go)
Apr 8, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Moderate
CVE-2026-33174
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service
Moderate
CVE-2026-26931
was published
for
github.com/elastic/beats/v7
(Go)
Mar 19, 2026
ProTip!
Advisories are also available from the
GraphQL API