GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,322 advisories
Filter by severity
Duplicate Advisory: Hackney has an Allocation of Resources Without Limits or Throttling vulnerabilit
High
GHSA-76v6-f83q-pxvh
was published
for
hackney
(Erlang)
May 26, 2026
•
withdrawn
Go Net HTML parser is vulnerable to denial of service
Moderate
CVE-2026-25680
was published
for
golang.org/x/net
(Go)
May 26, 2026
Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory
Moderate
CVE-2026-5755
was published
for
github.com/mattermost/mattermost-server
(Go)
May 26, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints
High
CVE-2026-5308
was published
for
github.com/mattermost/mattermost-plugin-github
(Go)
May 26, 2026
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
High
GHSA-7m8f-hgjq-8gc9
was published
for
aiosend
(pip)
May 22, 2026
js-libp2p: Memory DoS via subscription flood of unique topics
High
CVE-2026-46679
was published
for
@libp2p/gossipsub
(npm)
May 21, 2026
SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
High
CVE-2026-46374
was published
for
sqlfluff
(pip)
May 19, 2026
@libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes
High
CVE-2026-45783
was published
for
@libp2p/kad-dht
(npm)
May 19, 2026
FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
Moderate
CVE-2026-45802
was published
for
setasign/fpdi
(Composer)
May 19, 2026
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
High
CVE-2026-45713
was published
for
github.com/axllent/mailpit
(Go)
May 19, 2026
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
High
CVE-2026-46522
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
ImageMagick: Policy Bypass in MNG coder could
Moderate
CVE-2026-45664
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU
Moderate
CVE-2026-45680
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
ImageMagick: Policy Bypass in PSD decoder
Moderate
CVE-2026-45031
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
iskorotkov/avro: CPU Exhaustion in Decoder
High
CVE-2026-46385
was published
for
github.com/iskorotkov/avro/v2
(Go)
May 18, 2026
brace-expansion: Large numeric range defeats documented `max` DoS protection
Moderate
CVE-2026-45149
was published
for
brace-expansion
(npm)
May 18, 2026
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
High
GHSA-mx64-mj3q-7prj
was published
for
github.com/iskorotkov/avro/v2
(Go)
May 18, 2026
@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
Low
CVE-2026-8769
was published
for
@ai-sdk/provider-utils
(npm)
May 18, 2026
smtp-server's command parser memory exhaustion denial-of-service
High
CVE-2026-38728
was published
for
smtp-server
(npm)
May 15, 2026
Synapse CPU starvation (Denial of Service)
High
CVE-2026-45078
was published
for
matrix-synapse
(pip)
May 14, 2026
wger has an Uncontrolled Resource Consumption issue
Moderate
GHSA-v25j-wqcw-fvhj
was published
for
wger
(pip)
May 13, 2026
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
Moderate
CVE-2026-44796
was published
for
nautobot
(pip)
May 13, 2026
OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS
Moderate
CVE-2026-42073
was published
for
@gitlawb/openclaude
(npm)
May 12, 2026
Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS
Moderate
CVE-2026-32686
was published
for
decimal
(Erlang)
May 12, 2026
aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function
Moderate
CVE-2026-8319
was published
for
ai-agents
(pip)
May 11, 2026
ProTip!
Advisories are also available from the
GraphQL API