GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
248 advisories
Filter by severity
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Moderate
CVE-2026-54712
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Critical
GHSA-68r5-9hpg-7qw9
was published
for
org.openidentityplatform.opendj:opendj-dsml-servlet
(Maven)
Jul 24, 2026
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
High
GHSA-v74w-7mr3-4qg3
was published
for
io.netty:netty-codec-xml
(Maven)
Jul 24, 2026
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
High
CVE-2024-7708
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
High
CVE-2026-56816
was published
for
io.netty:netty-codec-http3
(Maven)
Jul 22, 2026
Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
High
CVE-2026-56745
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
High
CVE-2026-55851
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jul 22, 2026
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
High
CVE-2026-55833
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Netty SPDY SETTINGS frame count materializes unbounded settings map
High
CVE-2026-55831
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50270
was published
for
com.datadoghq:dd-java-agent
(Maven)
Jul 15, 2026
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
High
CVE-2026-44891
was published
for
io.netty:netty-codec-stomp
(Maven)
Jul 14, 2026
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
High
CVE-2026-49485
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
(Maven)
Jul 9, 2026
jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()
Moderate
CVE-2026-50193
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
High
CVE-2026-56740
was published
for
org.jline:jline-remote-telnet
(Maven)
Jun 18, 2026
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
High
CVE-2026-56741
was published
for
org.jline:jline-remote-telnet
(Maven)
Jun 18, 2026
Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
High
CVE-2026-50011
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 15, 2026
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
Moderate
CVE-2026-48043
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 11, 2026
Acknowledgement extension out of memory
High
CVE-2025-53114
was published
for
org.cometd.java:cometd-java-server-common
(Maven)
Jun 10, 2026
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
Moderate
CVE-2026-47244
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 8, 2026
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
High
CVE-2026-44892
was published
for
io.netty:netty-codec-http3
(Maven)
Jun 8, 2026
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
High
CVE-2026-44890
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 8, 2026
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
High
CVE-2026-44250
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 8, 2026
Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer
High
CVE-2026-49361
was published
for
org.apache.fluss:fluss-common
(Maven)
Jun 1, 2026
Netty MQTT: Resource exhaustion in MqttDecoder
Moderate
CVE-2026-44248
was published
for
io.netty:netty-codec-mqtt
(Maven)
May 7, 2026
ProTip!
Advisories are also available from the
GraphQL API