GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,042 advisories
Filter by severity
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not...
Critical
Unreviewed
CVE-2025-71401
was published
Aug 2, 2026
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
Moderate
GHSA-3fvr-2jw6-crq4
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream...
Moderate
Unreviewed
CVE-2026-67317
was published
Aug 1, 2026
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding:...
High
Unreviewed
CVE-2026-67297
was published
Aug 1, 2026
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
Moderate
GHSA-3whf-vgf2-9w6g
was published
for
zaino-state
(Rust)
Jul 31, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Moderate
CVE-2026-52857
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
An allocation of resources without limits vulnerability in the HTTP handler component of Google...
Moderate
Unreviewed
CVE-2026-14539
was published
Jul 31, 2026
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper...
High
Unreviewed
CVE-2026-12733
was published
Jul 30, 2026
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus...
High
Unreviewed
CVE-2026-16308
was published
Jul 30, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of...
High
Unreviewed
CVE-2026-11897
was published
Jul 30, 2026
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
High
CVE-2026-67432
was published
for
mcp
(RubyGems)
Jul 30, 2026
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
Moderate
CVE-2026-67430
was published
for
mcp
(RubyGems)
Jul 30, 2026
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
Moderate
CVE-2026-63119
was published
for
mcp
(RubyGems)
Jul 30, 2026
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
High
CVE-2026-67437
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA...
Moderate
Unreviewed
CVE-2026-16971
was published
Jul 30, 2026
The IRIS web application in version 2.4.26 and possibly others does not protect its user...
Moderate
Unreviewed
CVE-2026-18362
was published
Jul 30, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19...
High
Unreviewed
CVE-2026-15975
was published
Jul 29, 2026
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
High
CVE-2026-54638
was published
for
github.com/gotd/td
(Go)
Jul 28, 2026
NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints,...
High
Unreviewed
CVE-2026-47483
was published
Jul 28, 2026
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
Moderate
CVE-2026-54332
was published
for
github.com/gopacket/gopacket
(Go)
Jul 28, 2026
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
Moderate
CVE-2026-54345
was published
for
github.com/gopacket/gopacket
(Go)
Jul 28, 2026
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
High
CVE-2026-61609
was published
for
pterodactyl/panel
(Composer)
Jul 28, 2026
Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an...
Moderate
Unreviewed
CVE-2026-65624
was published
Jul 28, 2026
Allocation of resources without limits vulnerability in ninenines cowlib allows an...
High
Unreviewed
CVE-2026-59248
was published
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API