GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
104
GitHub Actions
54
Go
4,450
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,134
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,321 advisories
Filter by severity
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
Moderate
CVE-2026-48988
was published
for
markdown-it
(npm)
Jun 15, 2026
python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
High
CVE-2026-53539
was published
for
python-multipart
(pip)
Jun 15, 2026
UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`
Moderate
CVE-2026-48125
was published
for
ua-parser-js
(npm)
Jun 15, 2026
Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability
High
CVE-2026-45591
was published
for
Microsoft.AspNetCore.App.Runtime.linux-x64
(NuGet)
Jun 15, 2026
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
Moderate
CVE-2026-48525
was published
for
pyjwt
(pip)
Jun 15, 2026
@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
High
CVE-2026-54268
was published
for
@angular/common
(npm)
Jun 15, 2026
@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
High
CVE-2026-50171
was published
for
@angular/common
(npm)
Jun 15, 2026
ws: Memory exhaustion DoS from tiny fragments and data chunks
High
CVE-2026-48779
was published
for
ws
(npm)
Jun 15, 2026
File Browser has a DoS Vulnerability via Public Login API
High
CVE-2026-54092
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
pypdf: Possible large memory usage for large offsets for layout mode text
Moderate
CVE-2026-48155
was published
for
pypdf
(pip)
Jun 12, 2026
SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS
High
CVE-2026-28980
was published
for
github.com/apple/swift-nio
(Swift)
Jun 12, 2026
Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS
High
CVE-2026-48050
was published
for
github.com/basekick-labs/arc
(Go)
Jun 11, 2026
python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
Moderate
CVE-2026-48045
was published
for
zeroconf
(pip)
Jun 11, 2026
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
Moderate
CVE-2026-48043
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 11, 2026
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
High
CVE-2026-48069
was published
for
@grpc/grpc-js
(npm)
Jun 11, 2026
joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
Moderate
CVE-2026-48038
was published
for
joi
(npm)
Jun 11, 2026
Acknowledgement extension out of memory
High
CVE-2025-53114
was published
for
org.cometd.java:cometd-java-server-common
(Maven)
Jun 10, 2026
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
High
CVE-2026-47736
was published
for
puma
(RubyGems)
Jun 8, 2026
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
Moderate
CVE-2026-47734
was published
for
dulwich
(pip)
Jun 8, 2026
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
Moderate
CVE-2026-47244
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 8, 2026
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
High
CVE-2026-44892
was published
for
io.netty:netty-codec-http3
(Maven)
Jun 8, 2026
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
High
CVE-2026-44890
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 8, 2026
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
High
CVE-2026-44250
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 8, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
CVE-2026-49235
was published
for
routinator
(Rust)
Jun 8, 2026
Bugsink: DOS using large numbers of event tags
Moderate
CVE-2026-53954
was published
for
bugsink
(pip)
Jun 5, 2026
ProTip!
Advisories are also available from the
GraphQL API