Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36 advisories

Loading
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding High
CVE-2026-77354 was published for github.com/getkin/kin-openapi (Go) Aug 21, 2026
matiasinsaurralde Credited to matiasinsaurralde
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS High
CVE-2026-55149 was published for github.com/vouch/vouch-proxy (Go) Aug 20, 2026
EQSTLab Credited to EQSTLab
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM Moderate
CVE-2026-52857 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
WilliamVenner Credited to WilliamVenner
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode High
CVE-2026-54638 was published for github.com/gotd/td (Go) Jul 28, 2026
ayman148754-cloud Credited to ayman148754-cloud
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header Moderate
CVE-2026-53717 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
zhaohuabing Credited to zhaohuabing
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit Moderate
CVE-2026-53716 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
zhaohuabing Credited to zhaohuabing
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser High
CVE-2026-54448 was published for github.com/aquasecurity/trivy (Go) Jul 14, 2026
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service Moderate
CVE-2026-55079 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
opentelemetry-go's baggage parsing no longer caps raw header length Moderate
CVE-2026-41178 was published for go.opentelemetry.io/otel/baggage (Go) May 28, 2026
pellared Credited to pellared and XSAM XSAM XSAM
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation High
CVE-2026-5740 was published for github.com/mattermost/mattermost-server (Go) May 26, 2026
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder High
GHSA-mx64-mj3q-7prj was published for github.com/iskorotkov/avro/v2 (Go) May 18, 2026
klajok Credited to klajok
Mattermost doesn't validate 7zip archive structure before processing Moderate
CVE-2026-6340 was published for github.com/mattermost/mattermost-server (Go) May 18, 2026
Prometheus: Remote read endpoint allows denial of service via crafted snappy payload High
CVE-2026-42154 was published for github.com/prometheus/prometheus (Go) May 5, 2026
ShadowByte1 Credited to ShadowByte1, Ankush-Pathak, and noren95 Ankush-Pathak Ankush-Pathak
noren95 noren95
go-zserio has Unbounded Memory Allocation for All Platforms Critical
GHSA-xhj4-g6w8-2xjw was published for github.com/woven-planet/go-zserio (Go) Apr 24, 2026
Ryujiyasu Credited to Ryujiyasu
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing High
CVE-2026-40303 was published for github.com/openziti/zrok (Go) Apr 16, 2026
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies Moderate
CVE-2026-39882 was published for go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp (Go) Apr 8, 2026
1seal Credited to 1seal and pellared pellared pellared
Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service Moderate
CVE-2026-26931 was published for github.com/elastic/beats/v7 (Go) Mar 19, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports Moderate
CVE-2026-32941 was published for github.com/bishopfox/sliver (Go) Mar 17, 2026
skoveit Credited to skoveit
Mattermost fails to limit the size of responses from integration action endpoints Moderate
CVE-2026-2456 was published for github.com/mattermost/mattermost-server (Go) Mar 16, 2026
Mattermost fails to bound memory allocation when processing DOC files Moderate
CVE-2026-25780 was published for github.com/mattermost/mattermost-server (Go) Mar 16, 2026
Mattermost fails to bound memory allocation when processing PSD image files Moderate
CVE-2026-26246 was published for github.com/mattermost/mattermost-server (Go) Mar 16, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation High
CVE-2026-25899 was published for github.com/gofiber/fiber/v3 (Go) Feb 24, 2026
tuliperis Credited to tuliperis and gaby gaby gaby
EVE Freely Allocates Buffer on The Stack With Data From Socket Moderate
CVE-2023-43632 was published for github.com/lf-edge/eve (Go) Feb 4, 2026
yunfachi Credited to yunfachi
rardecode: DoS risk due to unrestricted RAR dictionary sizes Moderate
CVE-2025-11579 was published for github.com/nwaples/rardecode (Go) Oct 10, 2025
kzantow Credited to kzantow
ProTip! Advisories are also available from the GraphQL API