GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,005 advisories
Filter by severity
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
High
CVE-2026-64868
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Moderate
CVE-2026-54465
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Moderate
CVE-2026-54463
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an...
High
Unreviewed
CVE-2026-73634
was published
Aug 15, 2026
OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init...
Low
Unreviewed
CVE-2026-74797
was published
Aug 16, 2026
Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop...
High
Unreviewed
CVE-2026-74789
was published
Aug 16, 2026
Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression...
High
Unreviewed
CVE-2026-74785
was published
Aug 16, 2026
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing...
High
Unreviewed
CVE-2026-73057
was published
Aug 16, 2026
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested,...
High
Unreviewed
CVE-2026-33818
was published
Aug 14, 2026
A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an...
Moderate
Unreviewed
CVE-2026-19830
was published
Aug 14, 2026
Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an...
High
Unreviewed
CVE-2026-73633
was published
Aug 14, 2026
pyasn1 has a DoS vulnerability in decoder
High
CVE-2026-23490
was published
for
pyasn1
(pip)
Jan 16, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to...
Moderate
Unreviewed
CVE-2026-17078
was published
Aug 13, 2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Moderate
CVE-2026-73559
was published
for
vllm
(pip)
Aug 13, 2026
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
High
CVE-2026-54428
was published
for
org.apache.httpcomponents.core5:httpcore5-h2
(Maven)
Jul 1, 2026
libp2p: yamux connection DoS via oversized data frame
High
CVE-2026-73568
was published
for
libp2p
(pip)
Jul 24, 2026
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
High
CVE-2026-73561
was published
for
@anephenix/hub
(npm)
Jul 24, 2026
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
Moderate
CVE-2026-48043
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 11, 2026
Micrometer gRPC server instrumentation DoS
High
CVE-2026-40983
was published
for
io.micrometer:micrometer-core
(Maven)
Jun 9, 2026
Micrometer HTTP server instrumentations DoS
High
CVE-2026-40984
was published
for
io.micrometer:micrometer-core
(Maven)
Jun 9, 2026
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
High
CVE-2026-73507
was published
for
io.netty:netty-codec-xml
(Maven)
Jul 24, 2026
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon...
High
Unreviewed
CVE-2026-18358
was published
Jul 31, 2026
Shescape: Quadratic-time denial of service in the flag-protection
High
CVE-2026-73413
was published
for
shescape
(npm)
Jul 24, 2026
Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service
High
CVE-2026-54399
was published
for
org.apache.httpcomponents.core5:httpcore5
(Maven)
Jul 1, 2026
ProTip!
Advisories are also available from the
GraphQL API