GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,450
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,134
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
3,852 advisories
Filter by severity
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids...
High
Unreviewed
CVE-2026-66142
was published
Jul 24, 2026
Although remote policy references are not retrieved during policy normalization, if they are...
High
Unreviewed
CVE-2026-66144
was published
Jul 24, 2026
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
High
CVE-2026-59939
was published
for
httplib2
(pip)
Jul 24, 2026
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
Low
GHSA-qh5g-q395-cx4j
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
High
CVE-2026-55685
was published
for
react-router
(npm)
Jul 24, 2026
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
Moderate
CVE-2026-55595
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
Moderate
CVE-2026-55594
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
pypdf: Possible infinite loop for not terminated inline images
High
CVE-2026-59936
was published
for
pypdf
(pip)
Jul 23, 2026
pypdf: Possible long runtimes for repeated malformed cross-reference entries
Moderate
CVE-2026-59937
was published
for
pypdf
(pip)
Jul 23, 2026
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
High
CVE-2026-59933
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
High
CVE-2026-59932
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test)...
Moderate
Unreviewed
CVE-2026-21723
was published
Jul 23, 2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a...
Moderate
Unreviewed
CVE-2026-38763
was published
Jul 23, 2026
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
High
CVE-2024-7708
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Moderate
CVE-2026-59942
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
Moderate
CVE-2026-59941
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
High
CVE-2026-56816
was published
for
io.netty:netty-codec-http3
(Maven)
Jul 22, 2026
Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
High
CVE-2026-56745
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
High
CVE-2026-55851
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jul 22, 2026
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
High
CVE-2026-55833
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Netty SPDY SETTINGS frame count materializes unbounded settings map
High
CVE-2026-55831
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A...
Moderate
Unreviewed
CVE-2026-45820
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via...
Moderate
Unreviewed
CVE-2026-63263
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-63260
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API