GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,042 advisories
Filter by severity
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20...
Moderate
Unreviewed
CVE-2026-10600
was published
Jul 27, 2026
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings...
High
Unreviewed
CVE-2026-58389
was published
Jul 27, 2026
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings...
Moderate
Unreviewed
CVE-2026-45112
was published
Jul 27, 2026
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
High
CVE-2026-73500
was published
for
go.etcd.io/etcd/v3
(Go)
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
CVE-2026-16756
was published
for
aws-smithy-http-server
(Rust)
Jul 24, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries
High
GHSA-fp43-vj7g-pg92
was published
for
org.omnifaces:omnifaces
(Maven)
Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
High
CVE-2026-73493
was published
for
org.http4s:http4s-blaze-server_2.12
(Maven)
Jul 24, 2026
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
High
CVE-2026-14257
was published
for
brace-expansion
(npm)
Jul 24, 2026
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption...
High
Unreviewed
CVE-2026-66037
was published
Jul 24, 2026
react-server-dom: Denial of Service in Server Functions
High
CVE-2026-44907
was published
for
react-server-dom-parcel
(npm)
Jul 24, 2026
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
Moderate
CVE-2026-57497
was published
for
github.com/quic-go/webtransport-go
(Go)
Jul 24, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Moderate
CVE-2026-55497
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
High
CVE-2026-59939
was published
for
httplib2
(pip)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
High
GHSA-4w2j-m93h-cj5j
was published
for
quinn-proto
(Rust)
Jul 24, 2026
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
High
CVE-2026-55575
was published
for
liquidjs
(npm)
Jul 24, 2026
Allocation of resources without limits or throttling vulnerability in BizimHesap Information...
Moderate
Unreviewed
CVE-2026-8287
was published
Jul 23, 2026
Next.js: Unbounded Server Action payload in Edge runtime
Moderate
CVE-2026-64646
was published
for
next
(npm)
Jul 22, 2026
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Moderate
CVE-2026-59942
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
Moderate
CVE-2026-58661
was published
for
n8n
(npm)
Jul 22, 2026
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
Moderate
CVE-2026-59899
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by...
Moderate
Unreviewed
CVE-2026-13074
was published
Jul 22, 2026
An authenticated user can cause a {{mongod}} process to be terminated by the operating system...
High
Unreviewed
CVE-2026-13076
was published
Jul 22, 2026
An authenticated user can cause the mongod process to be terminated by the operating system under...
High
Unreviewed
CVE-2026-13075
was published
Jul 22, 2026
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a...
High
Unreviewed
CVE-2026-13069
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API