GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,410
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,502
Swift
61
Unreviewed advisories
All unreviewed
5,000+
1,952 advisories
Filter by severity
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
High
CVE-2026-59939
was published
for
httplib2
(pip)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
High
GHSA-4w2j-m93h-cj5j
was published
for
quinn-proto
(Rust)
Jul 24, 2026
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
High
CVE-2026-55575
was published
for
liquidjs
(npm)
Jul 24, 2026
Allocation of resources without limits or throttling vulnerability in BizimHesap Information...
Moderate
Unreviewed
CVE-2026-8287
was published
Jul 23, 2026
Next.js: Unbounded Server Action payload in Edge runtime
Moderate
CVE-2026-64646
was published
for
next
(npm)
Jul 22, 2026
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Moderate
CVE-2026-59942
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
Moderate
CVE-2026-58661
was published
for
n8n
(npm)
Jul 22, 2026
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
Moderate
CVE-2026-59899
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
An authenticated user can cause a {{mongod}} process to be terminated by the operating system...
High
Unreviewed
CVE-2026-13076
was published
Jul 22, 2026
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by...
Moderate
Unreviewed
CVE-2026-13074
was published
Jul 22, 2026
An authenticated user can cause the mongod process to be terminated by the operating system under...
High
Unreviewed
CVE-2026-13075
was published
Jul 22, 2026
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a...
High
Unreviewed
CVE-2026-13069
was published
Jul 22, 2026
Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar...
Moderate
Unreviewed
CVE-2026-65650
was published
Jul 22, 2026
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone...
High
Unreviewed
CVE-2026-11622
was published
Jul 22, 2026
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is...
Moderate
Unreviewed
CVE-2026-47013
was published
Jul 22, 2026
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
Moderate
GHSA-9mqv-5hh9-4cgg
was published
for
@hono/node-server
(npm)
Jul 21, 2026
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
High
GHSA-hrxh-6v49-42gf
was published
for
google.golang.org/grpc
(Go)
Jul 21, 2026
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
High
GHSA-r7wm-3cxj-wff9
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Jul 21, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of...
Moderate
Unreviewed
CVE-2026-42397
was published
Jul 21, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
Moderate
CVE-2026-42931
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
Moderate
CVE-2026-59763
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
High
CVE-2026-56170
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Jul 21, 2026
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs...
Moderate
Unreviewed
CVE-2026-59848
was published
Jul 21, 2026
Guzzle: Unbounded response cookies risk denial of service
Moderate
GHSA-f283-ghqc-fg79
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API