Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

248 advisories

Loading
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding High
CVE-2026-54609 was published for com.quietterminal:qti-neon (Maven) Jul 28, 2026
libp2p: yamux connection DoS via oversized data frame High
GHSA-hmj8-5xmh-5573 was published for libp2p (pip) Jul 24, 2026
tahaafarooq Credited to tahaafarooq
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling High
CVE-2026-59939 was published for httplib2 (pip) Jul 24, 2026
mauriceng98 Credited to mauriceng98
pypdf: Possible infinite loop for not terminated inline images High
CVE-2026-59936 was published for pypdf (pip) Jul 23, 2026
koltiradw Credited to koltiradw and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible long runtimes for repeated malformed cross-reference entries Moderate
CVE-2026-59937 was published for pypdf (pip) Jul 23, 2026
akahane0x46 Credited to akahane0x46 and stefan6419846 stefan6419846 stefan6419846
pyasn1: Uncontrolled resource consumption when converting decoded REAL values High
CVE-2026-59886 was published for pyasn1 (pip) Jul 21, 2026
gvozdila Credited to gvozdila
tynus2 Credited to tynus2
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs High
CVE-2026-59884 was published for pyssn1 (pip) Jul 21, 2026
mikeappsec Credited to mikeappsec
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() High
CVE-2026-59200 was published for Pillow (pip) Jul 20, 2026
redyank Credited to redyank
Tornado: Quadratic DoS via Crafted Multipart Parameters High
CVE-2025-67726 was published for tornado (pip) Jul 20, 2026
Finder16 Credited to Finder16
Tornado: Quadratic DoS via Repeated Header Coalescing High
CVE-2025-67725 was published for tornado (pip) Jul 20, 2026
Finder16 Credited to Finder16
vLLM: Speech-to-text upload size limit is enforced after full UploadFile read Moderate
CVE-2026-55646 was published for vllm (pip) Jul 17, 2026
rexpository Credited to rexpository and jperezdealgaba jperezdealgaba jperezdealgaba
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS High
CVE-2026-50271 was published for ddtrace (pip) Jul 15, 2026
0xmrma Credited to 0xmrma
Mistune: Potential DoS via quadratic-time parsing in parse_link_text High
CVE-2026-49851 was published for mistune (pip) Jul 9, 2026
bhanugoudm041 Credited to bhanugoudm041
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser High
CVE-2026-49477 was published for soupsieve (pip) Jul 9, 2026
mauriceng98 Credited to mauriceng98
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists High
CVE-2026-49476 was published for soupsieve (pip) Jul 9, 2026
mauriceng98 Credited to mauriceng98
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths High
GHSA-52vm-mxx8-f227 was published for phantom-audio (pip) Jul 9, 2026
leesaenz Credited to leesaenz
pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager Moderate
CVE-2026-48987 was published for pyload-ng (pip) Jul 9, 2026
pevinkumar10 Credited to pevinkumar10
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization Moderate
CVE-2026-48990 was published for joserfc (pip) Jun 26, 2026
0xHunSec Credited to 0xHunSec
Faze-up Credited to Faze-up
Langflow: Unauthenticated DoS through multipart form boundary file upload High
CVE-2026-55446 was published for langflow (pip) Jun 19, 2026
ethansilvas Credited to ethansilvas, AntonioABLima, and andifilhohub AntonioABLima AntonioABLima
andifilhohub andifilhohub
Ultimate Sitemap Parser (USP): Gzip Decompression Bomb Bypasses Sitemap Size Limit High
GHSA-8823-qg2x-pv9f was published for ultimate-sitemap-parser (pip) Jun 19, 2026
EQSTLab Credited to EQSTLab
pypdf: Missing stream length values ignore defined limits Moderate
GHSA-jm82-fx9c-mx94 was published for pypdf (pip) Jun 18, 2026
sondt99 Credited to sondt99 and stefan6419846 stefan6419846 stefan6419846
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak Critical
CVE-2026-55450 was published for langflow (pip) Jun 17, 2026
vbCrLf Credited to vbCrLf, Jkavia, erichare, AntonioABLima, andifilhohub, and Adam-Aghili Jkavia Jkavia
erichare erichare AntonioABLima AntonioABLima andifilhohub andifilhohub Adam-Aghili Adam-Aghili
ProTip! Advisories are also available from the GraphQL API