GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
58
GitHub Actions
50
Go
3,791
Maven
5,000+
npm
5,000+
NuGet
938
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,349
Swift
54
Unreviewed advisories
All unreviewed
5,000+
1,704 advisories
Filter by severity
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload
High
CVE-2026-44697
was published
for
github.com/klever-io/klever-go
(Go)
May 13, 2026
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue...
Unknown
Unreviewed
CVE-2026-41284
was published
May 12, 2026
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected...
High
Unreviewed
CVE-2026-22925
was published
May 12, 2026
Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components
High
CVE-2026-44579
was published
for
next
(npm)
May 11, 2026
Next.js has a Denial of Service in the Image Optimization API
Moderate
CVE-2026-44577
was published
for
next
(npm)
May 11, 2026
@vitejs/plugin-rsc has a Denial of Service Vulnerability in React Server Components
High
GHSA-w94c-4vhp-22gx
was published
for
@vitejs/plugin-rsc
(npm)
May 11, 2026
Next.js Vulnerable to Denial of Service with Server Components
High
GHSA-8h8q-6873-q5fj
was published
for
next
(npm)
May 11, 2026
Facebook React has a Denial of Service Vulnerability in React Server Components
High
CVE-2026-23870
was published
for
react-server-dom-parcel
(npm)
May 11, 2026
Volcano's webhook server vulnerable to OOM due to unbounded HTTP request body size
Moderate
CVE-2026-44247
was published
for
volcano.sh/volcano
(Go)
May 8, 2026
Phoenix: Long-poll NDJSON body splitting causes large memory allocation
High
CVE-2026-32689
was published
for
phoenix
(Erlang)
May 8, 2026
Zebra has Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning
High
CVE-2026-44499
was published
for
zebrad
(Rust)
May 8, 2026
@fastify/accepts-serializer Vulnerable to Denial of Service via Unbounded Accept Header Cache Growth
High
CVE-2026-7768
was published
for
@fastify/accepts-serializer
(npm)
May 8, 2026
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an...
Moderate
Unreviewed
CVE-2026-7541
was published
May 8, 2026
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
Moderate
GHSA-pj6q-4vq4-r8cg
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers
Moderate
CVE-2026-44500
was published
for
zebra-chain
(Rust)
May 7, 2026
Improperly controlled modification of Dynamically-Determined object attributes, Allocation of...
High
Unreviewed
CVE-2025-14341
was published
May 7, 2026
Bandit HTTP/2 Frame Size Limit Bypass via Late Buffer Check Enables Memory Exhaustion
Moderate
CVE-2026-42788
was published
for
bandit
(Erlang)
May 7, 2026
Bandit Buffers Unbounded WebSocket Continuation Frames, Allowing Unauthenticated Memory Exhaustion
High
CVE-2026-42786
was published
for
bandit
(Erlang)
May 7, 2026
Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame
High
CVE-2026-39804
was published
for
bandit
(Erlang)
May 7, 2026
hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression
Moderate
GHSA-q2qq-hmj6-3wpp
was published
for
hickory-proto
(Rust)
May 7, 2026
Netty Lz4FrameDecoder is vulnerable to resource exhaustion
High
CVE-2026-42583
was published
for
io.netty:netty-codec
(Maven)
May 7, 2026
Netty HTTP/3 QPACK literal unbounded allocation
High
CVE-2026-42582
was published
for
io.netty:netty-codec-http3
(Maven)
May 7, 2026
wasmtime has a panic when allocating a table exceeding the size of the host's address space
Moderate
CVE-2026-44216
was published
for
wasmtime
(Rust)
May 7, 2026
ldap3_proto has LDAP Filter stack exhaustion
High
GHSA-qcxq-75wr-5cm8
was published
for
ldap3_proto
(Rust)
May 6, 2026
Axonflow fixed bugs by implementing multi-tenant isolation and access-control hardening
Critical
GHSA-9h64-2846-7x7f
was published
for
github.com/getaxonflow/axonflow
(Go)
May 6, 2026
ProTip!
Advisories are also available from the
GraphQL API