Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7 advisories

Loading
Remote Code Execution in Gogs High
CVE-2024-44625 was published for gogs.io/gogs (Go) Nov 15, 2024
julianladisch Credited to julianladisch
Micrometer HTTP server instrumentations DoS High
CVE-2026-40984 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Micrometer gRPC server instrumentation DoS High
CVE-2026-40983 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem High
CVE-2026-40987 was published for org.springframework.integration:spring-integration-file (Maven) Jun 11, 2026
julianladisch Credited to julianladisch, oleg-andreev-check24, and ChristianAchatz oleg-andreev-check24 oleg-andreev-check24
ChristianAchatz ChristianAchatz
Apache cxf-core: No restriction on attachment headers per message High
CVE-2026-50645 was published for org.apache.cxf:cxf-core (Maven) Jun 12, 2026
julianladisch Credited to julianladisch, coheigea, and udengaardandersent-ELS coheigea coheigea
udengaardandersent-ELS udengaardandersent-ELS
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion High
CVE-2026-48748 was published for io.netty:netty-codec-http3 (Maven) Jun 15, 2026
violetagg Credited to violetagg and julianladisch julianladisch julianladisch
adm-zip: Crafted ZIP file triggers 4GB memory allocation High
CVE-2026-39244 was published for adm-zip (npm) Jul 10, 2026
julianladisch Credited to julianladisch
ProTip! Advisories are also available from the GraphQL API