GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
81 advisories
Filter by severity
pypdf: Possible long runtimes for repeated malformed cross-reference entries
Moderate
CVE-2026-59937
was published
for
pypdf
(pip)
Jul 23, 2026
vLLM: Speech-to-text upload size limit is enforced after full UploadFile read
Moderate
CVE-2026-55646
was published
for
vllm
(pip)
Jul 17, 2026
CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources
Moderate
GHSA-9mqm-qcwf-5qhg
was published
for
credsweeper
(pip)
Jul 10, 2026
pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager
Moderate
CVE-2026-48987
was published
for
pyload-ng
(pip)
Jul 9, 2026
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
Moderate
CVE-2026-48990
was published
for
joserfc
(pip)
Jun 26, 2026
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
Moderate
GHSA-4xgf-cpjx-pc3j
was published
for
pydantic-settings
(pip)
Jun 19, 2026
pypdf: Missing stream length values ignore defined limits
Moderate
GHSA-jm82-fx9c-mx94
was published
for
pypdf
(pip)
Jun 18, 2026
pypdf: Possible large memory usage for form XObjects during text extraction
Moderate
CVE-2026-49461
was published
for
pypdf
(pip)
Jun 16, 2026
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
Moderate
CVE-2026-48525
was published
for
pyjwt
(pip)
Jun 15, 2026
pypdf: Possible large memory usage for large offsets for layout mode text
Moderate
CVE-2026-48155
was published
for
pypdf
(pip)
Jun 12, 2026
python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
Moderate
CVE-2026-48045
was published
for
zeroconf
(pip)
Jun 11, 2026
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
Moderate
CVE-2026-47734
was published
for
dulwich
(pip)
Jun 8, 2026
Bugsink: DOS using large numbers of event tags
Moderate
CVE-2026-53954
was published
for
bugsink
(pip)
Jun 5, 2026
Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
Moderate
CVE-2026-47707
was published
for
strawberry-graphql
(pip)
Jun 4, 2026
Strawberry GraphQL has a Circular Fragment Reference DOS
Moderate
CVE-2026-47706
was published
for
strawberry-graphql
(pip)
Jun 4, 2026
hermes-agent has an Uncontrolled Resource Consumption issue
Moderate
CVE-2026-10224
was published
for
hermes-agent
(pip)
Jun 1, 2026
zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood
Moderate
CVE-2026-47184
was published
for
zeroconf
(pip)
May 29, 2026
zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
Moderate
CVE-2026-47183
was published
for
zeroconf
(pip)
May 29, 2026
wger has an Uncontrolled Resource Consumption issue
Moderate
GHSA-v25j-wqcw-fvhj
was published
for
wger
(pip)
May 13, 2026
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
Moderate
CVE-2026-44796
was published
for
nautobot
(pip)
May 13, 2026
aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function
Moderate
CVE-2026-8319
was published
for
ai-agents
(pip)
May 11, 2026
FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
Moderate
CVE-2026-6607
was published
for
fschat
(pip)
Apr 20, 2026
python-multipart affected by Denial of Service via large multipart preamble or epilogue data
Moderate
CVE-2026-40347
was published
for
python-multipart
(pip)
Apr 15, 2026
aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
Moderate
CVE-2026-22815
was published
for
aiohttp
(pip)
Apr 1, 2026
pypdf has inefficient decoding of array-based streams
Moderate
CVE-2026-33123
was published
for
pypdf
(pip)
Mar 18, 2026
ProTip!
Advisories are also available from the
GraphQL API