GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
83 advisories
Filter by severity
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
High
CVE-2026-59939
was published
for
httplib2
(pip)
Jul 24, 2026
pyasn1 has a DoS vulnerability in decoder
High
CVE-2026-23490
was published
for
pyasn1
(pip)
Jan 16, 2026
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
High
CVE-2026-59204
was published
for
pillow
(pip)
Jul 20, 2026
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
High
CVE-2026-59200
was published
for
Pillow
(pip)
Jul 20, 2026
Data exposure via ZeroMQ on multi-node vLLM deployment
High
CVE-2025-30202
was published
for
vllm
(pip)
Apr 29, 2025
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50271
was published
for
ddtrace
(pip)
Jul 15, 2026
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
High
CVE-2026-49476
was published
for
soupsieve
(pip)
Jul 9, 2026
python-socketio: Binary attachment accumulation can cause denial of service
High
CVE-2026-48804
was published
for
python-socketio
(pip)
Jun 26, 2026
python-engineio has unbound thread allocation that can cause denial of service
High
CVE-2026-48802
was published
for
python-engineio
(pip)
Jun 26, 2026
python-engineio has possible denial of service due to maximum payload size sometimes not being enforced
High
CVE-2026-48809
was published
for
python-engineio
(pip)
Jun 26, 2026
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
High
CVE-2026-54283
was published
for
starlette
(pip)
Jun 15, 2026
Synapse CPU starvation (Denial of Service)
High
CVE-2026-45078
was published
for
matrix-synapse
(pip)
May 14, 2026
strawberry-graphql: Denial of Service via unbounded WebSocket subscriptions
High
CVE-2026-35526
was published
for
strawberry-graphql
(pip)
Apr 6, 2026
Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)
High
CVE-2026-0897
was published
for
keras
(pip)
May 6, 2026
orjson does not limit recursion for deeply nested JSON documents
High
CVE-2025-67221
was published
for
orjson
(pip)
Jan 22, 2026
Synapse denial of service through media disk space consumption
High
CVE-2024-37302
was published
for
matrix-synapse
(pip)
Dec 3, 2024
Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
High
CVE-2026-33034
was published
for
Django
(pip)
Apr 7, 2026
python-multipart has Denial of Service via unbounded multipart part headers
High
CVE-2026-42561
was published
for
python-multipart
(pip)
May 6, 2026
Duplicate Advisory: Google Keras Allocates Resources Without Limits or Throttling in the HDF5 weight loading component
High
GHSA-xfhx-r7ww-5995
was published
for
keras
(pip)
Jan 15, 2026
•
withdrawn
FITS GZIP decompression bomb in Pillow
High
CVE-2026-40192
was published
for
pillow
(pip)
Apr 13, 2026
Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service
High
CVE-2026-34824
was published
for
mesop
(pip)
Apr 3, 2026
DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT
High
CVE-2026-33155
was published
for
deepdiff
(pip)
Mar 18, 2026
PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
High
CVE-2026-40116
was published
for
PraisonAI
(pip)
Apr 10, 2026
RAGAS has an Arbitrary File Read vulnerability
High
CVE-2025-45691
was published
for
ragas
(pip)
Mar 5, 2026
ProTip!
Advisories are also available from the
GraphQL API