Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

13 advisories

Loading
pypdf: Possible large memory usage for wrong image dimensions Moderate
CVE-2026-59938 was published for pypdf (pip) Jul 23, 2026
MR-SS Credited to MR-SS and stefan6419846 stefan6419846 stefan6419846
Brubbish Credited to Brubbish
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()` High
CVE-2026-55380 was published for pillow (pip) Jul 20, 2026
x-forwarded-sudo Credited to x-forwarded-sudo
x-forwarded-sudo Credited to x-forwarded-sudo
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()` High
CVE-2026-54060 was published for pillow (pip) Jul 20, 2026
dino320 Credited to dino320
kafka-python vulnerable to denial of service through an unvalidated protocol frame length High
CVE-2026-10142 was published for kafka-python (pip) Jun 11, 2026
hahwul Credited to hahwul
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs Moderate
CVE-2026-47734 was published for dulwich (pip) Jun 8, 2026
jelmer Credited to jelmer
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM Moderate
CVE-2026-41314 was published for pypdf (pip) Apr 16, 2026
l3b4nk4 Credited to l3b4nk4 and stefan6419846 stefan6419846 stefan6419846
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM Moderate
CVE-2026-41312 was published for pypdf (pip) Apr 16, 2026
l3b4nk4 Credited to l3b4nk4 and stefan6419846 stefan6419846 stefan6419846
Excessive Iteration in gRPC High
CVE-2023-33953 was published for grpc (RubyGems) Aug 9, 2023
levpachmanov Credited to levpachmanov
vyper vulnerable to storage allocator overflow High
CVE-2023-30837 was published for vyper (pip) May 5, 2023
ToonVanHove Credited to ToonVanHove and trocher trocher trocher
ProTip! Advisories are also available from the GraphQL API