GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
36 advisories
Filter by severity
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
High
CVE-2026-77354
was published
for
github.com/getkin/kin-openapi
(Go)
Aug 21, 2026
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
High
CVE-2026-55149
was published
for
github.com/vouch/vouch-proxy
(Go)
Aug 20, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Moderate
CVE-2026-52857
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
High
CVE-2026-54638
was published
for
github.com/gotd/td
(Go)
Jul 28, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
Moderate
CVE-2026-53717
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Moderate
CVE-2026-53716
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
High
CVE-2026-54448
was published
for
github.com/aquasecurity/trivy
(Go)
Jul 14, 2026
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
Moderate
CVE-2026-55079
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
opentelemetry-go's baggage parsing no longer caps raw header length
Moderate
CVE-2026-41178
was published
for
go.opentelemetry.io/otel/baggage
(Go)
May 28, 2026
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation
High
CVE-2026-5740
was published
for
github.com/mattermost/mattermost-server
(Go)
May 26, 2026
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
High
GHSA-mx64-mj3q-7prj
was published
for
github.com/iskorotkov/avro/v2
(Go)
May 18, 2026
Mattermost doesn't validate 7zip archive structure before processing
Moderate
CVE-2026-6340
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
Prometheus: Remote read endpoint allows denial of service via crafted snappy payload
High
CVE-2026-42154
was published
for
github.com/prometheus/prometheus
(Go)
May 5, 2026
go-zserio has Unbounded Memory Allocation for All Platforms
Critical
GHSA-xhj4-g6w8-2xjw
was published
for
github.com/woven-planet/go-zserio
(Go)
Apr 24, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
High
CVE-2026-40303
was published
for
github.com/openziti/zrok
(Go)
Apr 16, 2026
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
Moderate
CVE-2026-39882
was published
for
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp
(Go)
Apr 8, 2026
Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service
Moderate
CVE-2026-26931
was published
for
github.com/elastic/beats/v7
(Go)
Mar 19, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports
Moderate
CVE-2026-32941
was published
for
github.com/bishopfox/sliver
(Go)
Mar 17, 2026
Mattermost fails to limit the size of responses from integration action endpoints
Moderate
CVE-2026-2456
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost fails to bound memory allocation when processing DOC files
Moderate
CVE-2026-25780
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost fails to bound memory allocation when processing PSD image files
Moderate
CVE-2026-26246
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation
High
CVE-2026-25899
was published
for
github.com/gofiber/fiber/v3
(Go)
Feb 24, 2026
EVE Freely Allocates Buffer on The Stack With Data From Socket
Moderate
CVE-2023-43632
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpoints
Critical
CVE-2026-25579
was published
for
github.com/navidrome/navidrome
(Go)
Feb 4, 2026
rardecode: DoS risk due to unrestricted RAR dictionary sizes
Moderate
CVE-2025-11579
was published
for
github.com/nwaples/rardecode
(Go)
Oct 10, 2025
ProTip!
Advisories are also available from the
GraphQL API