GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
85 advisories
Filter by severity
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
CVE-2026-49755
was published
for
req
(Erlang)
Jul 29, 2026
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4...
Moderate
Unreviewed
CVE-2026-10819
was published
Jul 27, 2026
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift...
High
Unreviewed
CVE-2026-41608
was published
Jul 27, 2026
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C...
High
Unreviewed
CVE-2026-48586
was published
Jul 27, 2026
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift...
High
Unreviewed
CVE-2026-49158
was published
Jul 27, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Moderate
CVE-2026-55497
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
High
CVE-2026-59939
was published
for
httplib2
(pip)
Jul 24, 2026
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
High
CVE-2026-59932
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
High
CVE-2026-56755
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files
Moderate
GHSA-xg43-5579-qw6v
was published
for
adawolfa/isdoc
(Composer)
Jul 15, 2026
Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The...
High
Unreviewed
CVE-2026-61449
was published
Jul 15, 2026
A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate...
High
Unreviewed
CVE-2026-15709
was published
Jul 14, 2026
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data...
Moderate
Unreviewed
CVE-2026-12588
was published
Jul 14, 2026
CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources
Moderate
GHSA-9mqm-qcwf-5qhg
was published
for
credsweeper
(pip)
Jul 10, 2026
Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that...
High
Unreviewed
CVE-2026-61455
was published
Jul 10, 2026
Tesla has decompression bomb on response body
High
CVE-2026-48594
was published
for
tesla
(Erlang)
Jul 10, 2026
rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in...
High
Unreviewed
CVE-2026-59803
was published
Jul 8, 2026
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
Moderate
CVE-2026-55078
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause...
High
Unreviewed
CVE-2026-24264
was published
Jul 1, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
High
CVE-2026-44160
was published
for
fluentd
(RubyGems)
Jun 26, 2026
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
Moderate
CVE-2026-48510
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
High
CVE-2026-48502
was published
for
MessagePack
(NuGet)
Jun 25, 2026
py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size
Moderate
CVE-2026-55195
was published
for
py7zr
(pip)
Jun 19, 2026
vLLM: OOM Denial of Service via Audio Decompression Bomb
Moderate
CVE-2026-54233
was published
for
vllm
(pip)
Jun 17, 2026
n8n: Denial of Service via ZIP decompression in webhook workflow
Moderate
CVE-2026-54314
was published
for
n8n
(npm)
Jun 16, 2026
ProTip!
Advisories are also available from the
GraphQL API