GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
218 advisories
Filter by severity
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
Shescape: Quadratic-time denial of service in the flag-protection
High
GHSA-gm3r-q2wp-hw87
was published
for
shescape
(npm)
Jul 24, 2026
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
High
CVE-2026-14257
was published
for
brace-expansion
(npm)
Jul 24, 2026
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
High
GHSA-g5vv-q72c-7j78
was published
for
@anephenix/hub
(npm)
Jul 24, 2026
react-server-dom: Denial of Service in Server Functions
High
CVE-2026-44907
was published
for
react-server-dom-parcel
(npm)
Jul 24, 2026
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
High
CVE-2026-55685
was published
for
react-router
(npm)
Jul 24, 2026
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
High
CVE-2026-59879
was published
for
immutable
(npm)
Jul 21, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption
High
CVE-2026-59869
was published
for
js-yaml
(npm)
Jul 20, 2026
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
High
CVE-2026-13149
was published
for
brace-expansion
(npm)
Jul 20, 2026
dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50272
was published
for
dd-trace
(npm)
Jul 15, 2026
adm-zip: Crafted ZIP file triggers 4GB memory allocation
High
CVE-2026-39244
was published
for
adm-zip
(npm)
Jul 10, 2026
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
High
CVE-2026-49866
was published
for
@libp2p/gossipsub
(npm)
Jul 10, 2026
js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
High
CVE-2026-49293
was published
for
js-toml
(npm)
Jun 26, 2026
SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
High
GHSA-xcqx-9jf5-w339
was published
for
mcp-searxng
(npm)
Jun 19, 2026
undici WebSocket client vulnerable to denial of service via fragment count bypass
High
CVE-2026-12151
was published
for
undici
(npm)
Jun 19, 2026
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
High
CVE-2026-9675
was published
for
undici
(npm)
Jun 18, 2026
Multer vulnerable to Denial of Service via deeply nested field names
High
CVE-2026-5079
was published
for
multer
(npm)
Jun 17, 2026
@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
High
CVE-2026-54268
was published
for
@angular/common
(npm)
Jun 15, 2026
@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
High
CVE-2026-50171
was published
for
@angular/common
(npm)
Jun 15, 2026
ws: Memory exhaustion DoS from tiny fragments and data chunks
High
CVE-2026-48779
was published
for
ws
(npm)
Jun 15, 2026
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
High
CVE-2026-48069
was published
for
@grpc/grpc-js
(npm)
Jun 11, 2026
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
High
CVE-2026-44496
was published
for
axios
(npm)
Jun 4, 2026
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
High
CVE-2026-42342
was published
for
@remix-run/server-runtime
(npm)
Jun 3, 2026
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
High
CVE-2026-45357
was published
for
liquidjs
(npm)
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API