Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

793 advisories

Loading
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline High
CVE-2026-73500 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server High
CVE-2026-73493 was published for org.http4s:http4s-blaze-server_2.12 (Maven) Jul 24, 2026
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys High
CVE-2026-41716 was published for org.springframework.data:spring-data-commons (Maven) Jun 10, 2026
Gophish contains a denial of service vulnerability High
CVE-2026-39904 was published for github.com/gophish/gophish (Go) Jun 22, 2026
ashikmd7 Credited to ashikmd7
Micrometer HTTP server instrumentations DoS High
CVE-2026-40984 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Micrometer gRPC server instrumentation DoS High
CVE-2026-40983 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
dinhvaren Credited to dinhvaren
manop55555 Credited to manop55555
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory Moderate
CVE-2026-71310 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion High
CVE-2026-48748 was published for io.netty:netty-codec-http3 (Maven) Jun 15, 2026
violetagg Credited to violetagg and julianladisch julianladisch julianladisch
Guzzle: Unbounded response cookies risk denial of service Moderate
CVE-2026-67353 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service Moderate
GHSA-3fvr-2jw6-crq4 was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition Moderate
GHSA-72hv-8253-57qq was published for com.fasterxml.jackson.core:jackson-core (Maven) Feb 28, 2026
sprabhav7 Credited to sprabhav7, rohan-repos, neilmadden-hazelcast, awsactran, and cowtowncoder rohan-repos rohan-repos
neilmadden-hazelcast neilmadden-hazelcast awsactran awsactran cowtowncoder cowtowncoder
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) High
GHSA-r7wm-3cxj-wff9 was published for com.fasterxml.jackson.core:jackson-core (Maven) Jul 21, 2026
tonghuaroot Credited to tonghuaroot, pjfanning, and cowtowncoder pjfanning pjfanning
cowtowncoder cowtowncoder
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation High
CVE-2026-69152 was published for brace-expansion (npm) Aug 3, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit Moderate
GHSA-3whf-vgf2-9w6g was published for zaino-state (Rust) Jul 31, 2026
ouicate Credited to ouicate
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash High
CVE-2026-14257 was published for brace-expansion (npm) Jul 24, 2026
bnbdr Credited to bnbdr and G-Rath G-Rath G-Rath
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM Moderate
CVE-2026-52857 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
WilliamVenner Credited to WilliamVenner
Spring Framework Denial of Service via Unbounded Cache in SpEL Moderate
CVE-2026-41851 was published for org.springframework:spring-expression (Maven) Jun 9, 2026
hewei-gikaku Credited to hewei-gikaku
hewei-gikaku Credited to hewei-gikaku
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS) Moderate
CVE-2026-63119 was published for mcp (RubyGems) Jul 30, 2026
tonghuaroot Credited to tonghuaroot
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) High
CVE-2026-67437 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
knight-yagami Credited to knight-yagami
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service Moderate
CVE-2026-41710 was published for org.springframework.retry:spring-retry (Maven) Jun 9, 2026
Spring HATEOAS heap exhaustion through unbounded internal caching High
CVE-2026-41007 was published for org.springframework.hateoas:spring-hateoas (Maven) Jun 9, 2026
ProTip! Advisories are also available from the GraphQL API