GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,042 advisories
Filter by severity
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized...
High
Unreviewed
CVE-2026-49787
was published
Jul 14, 2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized...
High
Unreviewed
CVE-2026-45646
was published
Jul 14, 2026
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial...
Moderate
Unreviewed
CVE-2026-62641
was published
Jul 14, 2026
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions
Moderate
CVE-2026-50018
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Jul 14, 2026
A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from...
High
Unreviewed
CVE-2026-9140
was published
Jul 14, 2026
A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems...
High
Unreviewed
CVE-2026-10573
was published
Jul 14, 2026
A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected...
Moderate
Unreviewed
CVE-2026-54429
was published
Jul 14, 2026
ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation...
Moderate
Unreviewed
CVE-2026-61465
was published
Jul 11, 2026
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
High
CVE-2026-54063
was published
for
github.com/xuri/excelize/v2
(Go)
Jul 10, 2026
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
High
CVE-2026-49866
was published
for
@libp2p/gossipsub
(npm)
Jul 10, 2026
Duplicate Advisory: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
Moderate
GHSA-2vww-6p9h-5g8j
was published
for
n8n
(npm)
Jul 10, 2026
•
withdrawn
Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments...
Moderate
Unreviewed
CVE-2026-56309
was published
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
CVE-2026-48597
was published
for
tesla
(Erlang)
Jul 10, 2026
mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
High
CVE-2026-48862
was published
for
mint
(Erlang)
Jul 9, 2026
mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)
High
CVE-2026-49754
was published
for
mint
(Erlang)
Jul 9, 2026
Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer...
High
Unreviewed
CVE-2026-60108
was published
Jul 9, 2026
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
High
CVE-2026-49476
was published
for
soupsieve
(pip)
Jul 9, 2026
pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager
Moderate
CVE-2026-48987
was published
for
pyload-ng
(pip)
Jul 9, 2026
A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the...
High
Unreviewed
CVE-2026-31984
was published
Jul 9, 2026
HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push...
Moderate
Unreviewed
CVE-2026-14362
was published
Jul 8, 2026
App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value...
High
Unreviewed
CVE-2026-49146
was published
Jul 8, 2026
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
Moderate
Unreviewed
CVE-2026-60001
was published
Jul 8, 2026
sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource...
Low
Unreviewed
CVE-2026-60000
was published
Jul 8, 2026
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
Moderate
CVE-2026-55434
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
Moderate
CVE-2026-55078
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
ProTip!
Advisories are also available from the
GraphQL API