GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
237 advisories
Filter by severity
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Moderate
CVE-2026-55497
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Gitea SSH Key Parser Denial of Service
Moderate
CVE-2026-56657
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
File Browser has a DoS Vulnerability via Public Login API
High
CVE-2026-54092
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
Moderate
CVE-2026-52814
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
High
CVE-2026-50285
was published
for
github.com/pomerium/pomerium
(Go)
Jul 15, 2026
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50274
was published
for
github.com/DataDog/dd-trace-go
(Go)
Jul 15, 2026
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting
Moderate
CVE-2026-55512
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
High
CVE-2026-54448
was published
for
github.com/aquasecurity/trivy
(Go)
Jul 14, 2026
MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion
High
CVE-2026-50125
was published
for
github.com/StacklokLabs/mkp
(Go)
Jul 14, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions
Moderate
CVE-2026-50018
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Jul 14, 2026
Traefik: TCP readTimeout bypass via STARTTLS on Postgres
High
CVE-2026-25949
was published
for
github.com/traefik/traefik/v3
(Go)
Feb 12, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI
Moderate
CVE-2026-29049
was published
for
chainguard.dev/melange
(Go)
Mar 2, 2026
CosmWasm wasmd has large address count in ValidateBasic
Moderate
GHSA-m3rh-cvr5-x6q4
was published
for
github.com/CosmWasm/wasmd
(Go)
Aug 8, 2024
Go Net HTML parser is vulnerable to denial of service
Moderate
CVE-2026-25680
was published
for
golang.org/x/net
(Go)
May 26, 2026
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints
High
CVE-2026-5308
was published
for
github.com/mattermost/mattermost-plugin-github
(Go)
May 26, 2026
Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory
Moderate
CVE-2026-5755
was published
for
github.com/mattermost/mattermost-server
(Go)
May 26, 2026
containerd image-triggered runtime DoS via unbounded group parsing
Moderate
CVE-2026-47262
was published
for
github.com/containerd/containerd
(Go)
Jun 19, 2026
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
High
CVE-2026-32936
was published
for
github.com/coredns/coredns
(Go)
Apr 28, 2026
Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS
High
CVE-2026-48050
was published
for
github.com/basekick-labs/arc
(Go)
Jun 11, 2026
klever-go: REST API slow-header connection exhaustion via Gin Engine.Run
High
CVE-2026-52880
was published
for
github.com/klever-io/klever-go
(Go)
Jun 5, 2026
klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS
High
CVE-2026-52879
was published
for
github.com/klever-io/klever-go
(Go)
Jun 5, 2026
OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU
Moderate
CVE-2026-45680
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
iskorotkov/avro: CPU Exhaustion in Decoder
High
CVE-2026-46385
was published
for
github.com/iskorotkov/avro/v2
(Go)
May 18, 2026
Volcano's webhook server vulnerable to OOM due to unbounded HTTP request body size
Moderate
CVE-2026-44247
was published
for
volcano.sh/volcano
(Go)
May 8, 2026
Bird-lg-go has a Fatal Out-of-Memory (OOM) Denial of Service via Unbounded JSON Decoding
High
CVE-2026-45047
was published
for
github.com/xddxdd/bird-lg-go
(Go)
May 11, 2026
ProTip!
Advisories are also available from the
GraphQL API