Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,042 advisories

Loading
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline High
CVE-2026-73500 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server High
CVE-2026-73493 was published for org.http4s:http4s-blaze-server_2.12 (Maven) Jul 24, 2026
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash High
CVE-2026-14257 was published for brace-expansion (npm) Jul 24, 2026
bnbdr Credited to bnbdr and G-Rath G-Rath G-Rath
react-server-dom: Denial of Service in Server Functions High
CVE-2026-44907 was published for react-server-dom-parcel (npm) Jul 24, 2026
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules Moderate
CVE-2026-57497 was published for github.com/quic-go/webtransport-go (Go) Jul 24, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server Moderate
CVE-2026-55497 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
riodrwn Credited to riodrwn
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling High
CVE-2026-59939 was published for httplib2 (pip) Jul 24, 2026
mauriceng98 Credited to mauriceng98
ImageMagick: Policy Bypass possible with matrix-backed operations Low
GHSA-rvhp-75f6-9jqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly High
GHSA-4w2j-m93h-cj5j was published for quinn-proto (Rust) Jul 24, 2026
K-Rintaro Credited to K-Rintaro
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce High
CVE-2026-55575 was published for liquidjs (npm) Jul 24, 2026
offset Credited to offset
Next.js: Unbounded Server Action payload in Edge runtime Moderate
CVE-2026-64646 was published for next (npm) Jul 22, 2026
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps Moderate
CVE-2026-59942 was published for dompdf/dompdf (Composer) Jul 22, 2026
far00t01 Credited to far00t01
n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads Moderate
CVE-2026-58661 was published for n8n (npm) Jul 22, 2026
CodeByMoriarty Credited to CodeByMoriarty
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service Moderate
CVE-2026-59899 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
ProTip! Advisories are also available from the GraphQL API