Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,005 advisories

Loading
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging High
CVE-2026-64868 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
passer12 Credited to passer12
websocket-driver: Memory exhaustion in HTTP header parser Moderate
CVE-2026-54465 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
websocket-driver: Memory exhaustion via abuse of protocol length headers Moderate
CVE-2026-54463 was published for websocket-driver (RubyGems) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set High
CVE-2026-59880 was published for immutable (npm) Jul 21, 2026
nvth Credited to nvth and 36degrees 36degrees 36degrees
pyasn1 has a DoS vulnerability in decoder High
CVE-2026-23490 was published for pyasn1 (pip) Jan 16, 2026
tsigouris007 Credited to tsigouris007
vLLM: Completion prompt lists fan out into unbounded engine requests Moderate
CVE-2026-73559 was published for vllm (pip) Aug 13, 2026
rexpository Credited to rexpository, jperezdealgaba, and DarkLight1337 jperezdealgaba jperezdealgaba
DarkLight1337 DarkLight1337
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK High
CVE-2026-54428 was published for org.apache.httpcomponents.core5:httpcore5-h2 (Maven) Jul 1, 2026
Lueton Credited to Lueton
libp2p: yamux connection DoS via oversized data frame High
CVE-2026-73568 was published for libp2p (pip) Jul 24, 2026
tahaafarooq Credited to tahaafarooq
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion High
CVE-2026-73561 was published for @anephenix/hub (npm) Jul 24, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion Moderate
CVE-2026-48043 was published for io.netty:netty-codec-http2 (Maven) Jun 11, 2026
Micrometer gRPC server instrumentation DoS High
CVE-2026-40983 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Micrometer HTTP server instrumentations DoS High
CVE-2026-40984 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion High
CVE-2026-73507 was published for io.netty:netty-codec-xml (Maven) Jul 24, 2026
violetagg Credited to violetagg
Shescape: Quadratic-time denial of service in the flag-protection High
CVE-2026-73413 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service High
CVE-2026-54399 was published for org.apache.httpcomponents.core5:httpcore5 (Maven) Jul 1, 2026
tikri Credited to tikri
ProTip! Advisories are also available from the GraphQL API