GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
3,760 advisories
Filter by severity
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
High
CVE-2024-7708
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 22, 2026
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Moderate
CVE-2026-59942
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
Moderate
CVE-2026-59941
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
High
CVE-2026-56816
was published
for
io.netty:netty-codec-http3
(Maven)
Jul 22, 2026
This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0,...
High
Unreviewed
CVE-2026-21577
was published
Jul 21, 2026
Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
High
CVE-2026-56745
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
High
Unreviewed
CVE-2026-16376
was published
Jul 21, 2026
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size...
Moderate
Unreviewed
CVE-2026-59843
was published
Jul 21, 2026
Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
High
CVE-2026-55851
was published
for
io.netty:netty-codec-haproxy
(Maven)
Jul 22, 2026
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
High
CVE-2026-55833
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Netty SPDY SETTINGS frame count materializes unbounded settings map
High
CVE-2026-55831
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component:...
Low
Unreviewed
CVE-2026-62508
was published
Jul 22, 2026
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file...
High
Unreviewed
CVE-2023-52355
was published
Jan 25, 2024
fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A...
Moderate
Unreviewed
CVE-2026-45820
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-63261
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-63260
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via...
Moderate
Unreviewed
CVE-2026-63263
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via...
Moderate
Unreviewed
CVE-2026-56145
was published
Jul 21, 2026
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-63139
was published
Jul 21, 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via...
Moderate
Unreviewed
CVE-2026-63136
was published
Jul 21, 2026
Gitea SSH Key Parser Denial of Service
Moderate
CVE-2026-56657
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
pyasn1: Uncontrolled resource consumption when converting decoded REAL values
High
CVE-2026-59886
was published
for
pyasn1
(pip)
Jul 21, 2026
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
High
CVE-2026-59885
was published
for
pyasn1
(pip)
Jul 21, 2026
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
High
CVE-2026-59884
was published
for
pyssn1
(pip)
Jul 21, 2026
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API