Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,042 advisories

Loading
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake Moderate
GHSA-9mqv-5hh9-4cgg was published for @hono/node-server (npm) Jul 21, 2026
TarPeg007 Credited to TarPeg007
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities High
GHSA-hrxh-6v49-42gf was published for google.golang.org/grpc (Go) Jul 21, 2026
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) High
GHSA-r7wm-3cxj-wff9 was published for com.fasterxml.jackson.core:jackson-core (Maven) Jul 21, 2026
tonghuaroot Credited to tonghuaroot, pjfanning, and cowtowncoder pjfanning pjfanning
cowtowncoder cowtowncoder
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint Moderate
CVE-2026-42931 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Tricta Credited to Tricta
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads Moderate
CVE-2026-59763 was published for code.gitea.io/gitea (Go) Jul 21, 2026
kkkh1 Credited to kkkh1
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability High
CVE-2026-56170 was published for Microsoft.AspNetCore.App.Runtime.linux-arm (NuGet) Jul 21, 2026
Guzzle: Unbounded response cookies risk denial of service Moderate
CVE-2026-67353 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Phillip9587 Credited to Phillip9587, efekrskl, UlisesGascon, and bjohansebas efekrskl efekrskl
UlisesGascon UlisesGascon bjohansebas bjohansebas
Brubbish Credited to Brubbish
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() High
CVE-2026-59200 was published for Pillow (pip) Jul 20, 2026
redyank Credited to redyank
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability High
CVE-2026-50651 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability High
CVE-2026-50525 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
bribrothers Credited to bribrothers
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability High
CVE-2026-50648 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
bribrothers Credited to bribrothers
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability High
CVE-2026-47302 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
nmas321 Credited to nmas321, MattKilgore, bottarocarlo, and bribrothers MattKilgore MattKilgore
bottarocarlo bottarocarlo bribrothers bribrothers
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` Moderate
GHSA-jqh4-m9w3-8hp9 was published for axios (npm) Jul 20, 2026
asadeddin Credited to asadeddin
node-tar: Decompression/parse DoS via unlimited input Critical
CVE-2026-59873 was published for tar (npm) Jul 20, 2026
Jvr2022 Credited to Jvr2022
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml Moderate
CVE-2026-59868 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA Moderate
CVE-2026-59870 was published for js-yaml (npm) Jul 20, 2026
usama0x01 Credited to usama0x01
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service Moderate
GHSA-pmv8-rq9r-6j72 was published for axios (npm) Jul 20, 2026
sam-caldwell Credited to sam-caldwell
ProTip! Advisories are also available from the GraphQL API