Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

491 advisories

Loading
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion Moderate
CVE-2026-54712 was published for io.opentelemetry.javaagent:opentelemetry-javaagent (Maven) Jul 29, 2026
decsecre583 Credited to decsecre583
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server Moderate
CVE-2026-55497 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
riodrwn Credited to riodrwn
ImageMagick: Infinite Loop in connected-components when providing invalid arguments Moderate
CVE-2026-55595 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Stack Overflow in MVG decoder due to missing depth check. Moderate
CVE-2026-55594 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
pypdf: Possible long runtimes for repeated malformed cross-reference entries Moderate
CVE-2026-59937 was published for pypdf (pip) Jul 23, 2026
akahane0x46 Credited to akahane0x46 and stefan6419846 stefan6419846 stefan6419846
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps Moderate
CVE-2026-59942 was published for dompdf/dompdf (Composer) Jul 22, 2026
far00t01 Credited to far00t01
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions Moderate
CVE-2026-59941 was published for dompdf/dompdf (Composer) Jul 22, 2026
riodrwn Credited to riodrwn
Gitea SSH Key Parser Denial of Service Moderate
CVE-2026-56657 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Axios: HTTP/2 streamed uploads bypass `maxBodyLength` Moderate
GHSA-mwf2-3pr3-8698 was published for axios (npm) Jul 20, 2026
asadeddin Credited to asadeddin
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml Moderate
CVE-2026-59868 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
Axios: Excessive recursion in formDataToJSON can cause denial of service Moderate
GHSA-42h9-826w-cgv3 was published for axios (npm) Jul 20, 2026
alcls01111 Credited to alcls01111
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service Moderate
GHSA-pmv8-rq9r-6j72 was published for axios (npm) Jul 20, 2026
sam-caldwell Credited to sam-caldwell
vLLM: Speech-to-text upload size limit is enforced after full UploadFile read Moderate
CVE-2026-55646 was published for vllm (pip) Jul 17, 2026
rexpository Credited to rexpository and jperezdealgaba jperezdealgaba jperezdealgaba
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files Moderate
GHSA-xg43-5579-qw6v was published for adawolfa/isdoc (Composer) Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser Moderate
CVE-2026-54465 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
websocket-driver: Memory exhaustion via abuse of protocol length headers Moderate
CVE-2026-54463 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting Moderate
CVE-2026-55512 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions Moderate
CVE-2026-50018 was published for github.com/SpectoLabs/hoverfly (Go) Jul 14, 2026
Kr1shna4garwal Credited to Kr1shna4garwal
0xmrma Credited to 0xmrma
pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager Moderate
CVE-2026-48987 was published for pyload-ng (pip) Jul 9, 2026
pevinkumar10 Credited to pevinkumar10
ratex-parser has unbounded parser recursion that leads to stack overflow (process abort) Moderate
CVE-2026-53531 was published for ratex-parser (Rust) Jul 7, 2026
nikkoenggaliano Credited to nikkoenggaliano
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication) Moderate
CVE-2026-35365 was published for uu_mv (Rust) Jul 6, 2026
cp: -R reads device nodes as streams, destroying device semantics Moderate
CVE-2026-35358 was published for uu_cp (Rust) Jul 6, 2026
oban_web: Unbounded range expansion in cron describe causes memory exhaustion Moderate
CVE-2026-48593 was published for oban_web (Erlang) Jun 30, 2026
PJUllrich Credited to PJUllrich, sorenone, and maennchen sorenone sorenone
maennchen maennchen
ProTip! Advisories are also available from the GraphQL API