Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,852 advisories

Loading
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling High
CVE-2026-59939 was published for httplib2 (pip) Jul 24, 2026
mauriceng98 Credited to mauriceng98
ImageMagick: Heap-use-after-free via XMP profile could result in a crash Low
GHSA-qh5g-q395-cx4j was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass possible with matrix-backed operations Low
GHSA-rvhp-75f6-9jqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
React Router: Unauthenticated Denial of Service via Inefficient Route Matching High
CVE-2026-55685 was published for react-router (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
ImageMagick: Infinite Loop in connected-components when providing invalid arguments Moderate
CVE-2026-55595 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Stack Overflow in MVG decoder due to missing depth check. Moderate
CVE-2026-55594 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
pypdf: Possible infinite loop for not terminated inline images High
CVE-2026-59936 was published for pypdf (pip) Jul 23, 2026
koltiradw Credited to koltiradw and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible long runtimes for repeated malformed cross-reference entries Moderate
CVE-2026-59937 was published for pypdf (pip) Jul 23, 2026
akahane0x46 Credited to akahane0x46 and stefan6419846 stefan6419846 stefan6419846
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion High
CVE-2026-59933 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion High
CVE-2026-59932 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests High
CVE-2024-7708 was published for org.eclipse.jetty:jetty-server (Maven) Jul 22, 2026
kimmerin Credited to kimmerin and pmneo pmneo pmneo
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps Moderate
CVE-2026-59942 was published for dompdf/dompdf (Composer) Jul 22, 2026
far00t01 Credited to far00t01
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions Moderate
CVE-2026-59941 was published for dompdf/dompdf (Composer) Jul 22, 2026
riodrwn Credited to riodrwn
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types High
CVE-2026-56816 was published for io.netty:netty-codec-http3 (Maven) Jul 22, 2026
violetagg Credited to violetagg
Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion High
CVE-2026-56745 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion High
CVE-2026-55851 was published for io.netty:netty-codec-haproxy (Maven) Jul 22, 2026
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation High
CVE-2026-55833 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
Alexender676 Credited to Alexender676
Netty SPDY SETTINGS frame count materializes unbounded settings map High
CVE-2026-55831 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
Alexender676 Credited to Alexender676
ProTip! Advisories are also available from the GraphQL API