GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
793 advisories
Filter by severity
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
High
CVE-2026-73500
was published
for
go.etcd.io/etcd/v3
(Go)
Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
High
CVE-2026-73493
was published
for
org.http4s:http4s-blaze-server_2.12
(Maven)
Jul 24, 2026
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys
High
CVE-2026-41716
was published
for
org.springframework.data:spring-data-commons
(Maven)
Jun 10, 2026
Gophish contains a denial of service vulnerability
High
CVE-2026-39904
was published
for
github.com/gophish/gophish
(Go)
Jun 22, 2026
Micrometer HTTP server instrumentations DoS
High
CVE-2026-40984
was published
for
io.micrometer:micrometer-core
(Maven)
Jun 9, 2026
Micrometer gRPC server instrumentation DoS
High
CVE-2026-40983
was published
for
io.micrometer:micrometer-core
(Maven)
Jun 9, 2026
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
High
CVE-2026-71321
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
High
CVE-2026-71314
was published
for
nuxt
(npm)
Aug 5, 2026
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
Moderate
CVE-2026-71310
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
High
CVE-2026-48748
was published
for
io.netty:netty-codec-http3
(Maven)
Jun 15, 2026
Guzzle: Unbounded response cookies risk denial of service
Moderate
CVE-2026-67353
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
Moderate
GHSA-3fvr-2jw6-crq4
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
Moderate
GHSA-72hv-8253-57qq
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Feb 28, 2026
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
High
GHSA-r7wm-3cxj-wff9
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Jul 21, 2026
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
High
CVE-2026-69152
was published
for
brace-expansion
(npm)
Aug 3, 2026
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
Moderate
GHSA-3whf-vgf2-9w6g
was published
for
zaino-state
(Rust)
Jul 31, 2026
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
High
CVE-2026-14257
was published
for
brace-expansion
(npm)
Jul 24, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Moderate
CVE-2026-52857
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
Spring Framework Denial of Service via Unbounded Cache in SpEL
Moderate
CVE-2026-41851
was published
for
org.springframework:spring-expression
(Maven)
Jun 9, 2026
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
High
CVE-2026-67432
was published
for
mcp
(RubyGems)
Jul 30, 2026
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
Moderate
CVE-2026-67430
was published
for
mcp
(RubyGems)
Jul 30, 2026
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
Moderate
CVE-2026-63119
was published
for
mcp
(RubyGems)
Jul 30, 2026
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
High
CVE-2026-67437
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
Moderate
CVE-2026-41710
was published
for
org.springframework.retry:spring-retry
(Maven)
Jun 9, 2026
Spring HATEOAS heap exhaustion through unbounded internal caching
High
CVE-2026-41007
was published
for
org.springframework.hateoas:spring-hateoas
(Maven)
Jun 9, 2026
ProTip!
Advisories are also available from the
GraphQL API