GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,042 advisories
Filter by severity
Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar...
Moderate
Unreviewed
CVE-2026-65650
was published
Jul 22, 2026
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone...
High
Unreviewed
CVE-2026-11622
was published
Jul 22, 2026
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is...
Moderate
Unreviewed
CVE-2026-47013
was published
Jul 22, 2026
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
Moderate
GHSA-9mqv-5hh9-4cgg
was published
for
@hono/node-server
(npm)
Jul 21, 2026
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
High
GHSA-hrxh-6v49-42gf
was published
for
google.golang.org/grpc
(Go)
Jul 21, 2026
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
High
GHSA-r7wm-3cxj-wff9
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Jul 21, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of...
Moderate
Unreviewed
CVE-2026-42397
was published
Jul 21, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
Moderate
CVE-2026-42931
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
Moderate
CVE-2026-59763
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
High
CVE-2026-56170
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Jul 21, 2026
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs...
Moderate
Unreviewed
CVE-2026-59848
was published
Jul 21, 2026
Guzzle: Unbounded response cookies risk denial of service
Moderate
CVE-2026-67353
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
Low
CVE-2026-12590
was published
for
body-parser
(npm)
Jul 20, 2026
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
High
CVE-2026-59204
was published
for
pillow
(pip)
Jul 20, 2026
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
High
CVE-2026-59200
was published
for
Pillow
(pip)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
High
CVE-2026-50651
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
High
CVE-2026-50525
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
High
CVE-2026-50648
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
High
CVE-2026-47302
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
Moderate
GHSA-jqh4-m9w3-8hp9
was published
for
axios
(npm)
Jul 20, 2026
node-tar: Decompression/parse DoS via unlimited input
Critical
CVE-2026-59873
was published
for
tar
(npm)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
Moderate
CVE-2026-59868
was published
for
js-yaml
(npm)
Jul 20, 2026
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
Moderate
CVE-2026-59870
was published
for
js-yaml
(npm)
Jul 20, 2026
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
Moderate
GHSA-pmv8-rq9r-6j72
was published
for
axios
(npm)
Jul 20, 2026
SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to...
Moderate
Unreviewed
CVE-2026-63750
was published
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API