Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

92 advisories

Loading
kafka-python vulnerable to denial of service through an unvalidated protocol frame length High
CVE-2026-10142 was published for kafka-python (pip) Jun 11, 2026
hahwul Credited to hahwul
p80n-sec Credited to p80n-sec
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding High
CVE-2026-77354 was published for github.com/getkin/kin-openapi (Go) Aug 21, 2026
matiasinsaurralde Credited to matiasinsaurralde
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS High
CVE-2026-55149 was published for github.com/vouch/vouch-proxy (Go) Aug 20, 2026
EQSTLab Credited to EQSTLab
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation High
CVE-2026-69219 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
lucianjohnhouse Credited to lucianjohnhouse
manop55555 Credited to manop55555
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM Moderate
CVE-2026-52857 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
WilliamVenner Credited to WilliamVenner
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode High
CVE-2026-54638 was published for github.com/gotd/td (Go) Jul 28, 2026
ayman148754-cloud Credited to ayman148754-cloud
pypdf: Possible large memory usage for wrong image dimensions Moderate
CVE-2026-59938 was published for pypdf (pip) Jul 23, 2026
MR-SS Credited to MR-SS and stefan6419846 stefan6419846 stefan6419846
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability Moderate
CVE-2026-43868 was published for thrift (Rust) May 5, 2026
bayandin Credited to bayandin
Brubbish Credited to Brubbish
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()` High
CVE-2026-55380 was published for pillow (pip) Jul 20, 2026
x-forwarded-sudo Credited to x-forwarded-sudo
x-forwarded-sudo Credited to x-forwarded-sudo
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()` High
CVE-2026-54060 was published for pillow (pip) Jul 20, 2026
dino320 Credited to dino320
adm-zip: Crafted ZIP file triggers 4GB memory allocation High
CVE-2026-39244 was published for adm-zip (npm) Jul 10, 2026
julianladisch Credited to julianladisch
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header Moderate
CVE-2026-53717 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
zhaohuabing Credited to zhaohuabing
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit Moderate
CVE-2026-53716 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
zhaohuabing Credited to zhaohuabing
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser High
CVE-2026-54448 was published for github.com/aquasecurity/trivy (Go) Jul 14, 2026
ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation Moderate
CVE-2026-54700 was published for org.connectbot.sshlib:sshlib (Maven) Jun 12, 2026
kruton Credited to kruton
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing Moderate
CVE-2026-54697 was published for org.connectbot.sshlib:sshlib (Maven) Jun 12, 2026
Pig-Tail Credited to Pig-Tail and kruton kruton kruton
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service Moderate
CVE-2026-55079 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
Netty HTTP/3 QPACK literal unbounded allocation High
CVE-2026-42582 was published for io.netty:netty-codec-http3 (Maven) May 7, 2026
violetagg Credited to violetagg, nicolaideffremo, normanmaurer, and massif-01 nicolaideffremo nicolaideffremo
normanmaurer normanmaurer massif-01 massif-01
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation High
CVE-2026-5740 was published for github.com/mattermost/mattermost-server (Go) May 26, 2026
AArnott Credited to AArnott
ProTip! Advisories are also available from the GraphQL API