Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36 advisories

Loading
ImageMagick: Policy Bypass possible with matrix-backed operations Low
GHSA-rvhp-75f6-9jqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability High
CVE-2026-47302 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
nmas321 Credited to nmas321, MattKilgore, bottarocarlo, and bribrothers MattKilgore MattKilgore
bottarocarlo bottarocarlo bribrothers bribrothers
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability High
CVE-2026-50648 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
bribrothers Credited to bribrothers
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability High
CVE-2026-50525 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
bribrothers Credited to bribrothers
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability High
CVE-2026-56170 was published for Microsoft.AspNetCore.App.Runtime.linux-arm (NuGet) Jul 21, 2026
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability High
CVE-2026-50651 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS High
CVE-2026-50273 was published for Datadog.Trace (NuGet) Jul 15, 2026
Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString Moderate
GHSA-m2p3-hwv5-xpqw was published for Scriban (NuGet) Mar 24, 2026
offset Credited to offset and adamus2 adamus2 adamus2
Scriban: Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service High
GHSA-v66j-x4hw-fv9g was published for Scriban (NuGet) Mar 24, 2026
offset Credited to offset and adamus2 adamus2 adamus2
Scriban Affected by Memory Exhaustion (OOM) via Unbounded String Generation (Denial of Service) Moderate
GHSA-5rpf-x9jg-8j5p was published for Scriban.Signed (NuGet) Mar 19, 2026
adamus2 Credited to adamus2
MindflareX Credited to MindflareX and adamus2 adamus2 adamus2
Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString High
GHSA-24c8-4792-22hx was published for Scriban.Signed (NuGet) May 19, 2026
fg0x0 Credited to fg0x0 and adamus2 adamus2 adamus2
ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition High
CVE-2026-53460 was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 25, 2026
OwenSanzas Credited to OwenSanzas
MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions Moderate
CVE-2026-48515 was published for MessagePack (NuGet) Jun 25, 2026
AArnott Credited to AArnott
MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length Moderate
CVE-2026-48514 was published for MessagePack (NuGet) Jun 25, 2026
AArnott Credited to AArnott
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths Moderate
CVE-2026-48510 was published for MessagePack (NuGet) Jun 25, 2026
AArnott Credited to AArnott
NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation Moderate
CVE-2026-55254 was published for NCalc.Core (NuGet) Jun 18, 2026
pawlos Credited to pawlos and gumbarros gumbarros gumbarros
ImageMagick: Policy Bypass in PSD decoder Moderate
CVE-2026-45031 was published for Magick.NET-Q16-AnyCPU (NuGet) May 18, 2026
dayzsec Credited to dayzsec
OneCollector exporter reads unbounded HTTP response bodies Moderate
CVE-2026-41484 was published for OpenTelemetry.Exporter.OneCollector (NuGet) Apr 29, 2026
martincostello Credited to martincostello and rajkumar-rangaraj rajkumar-rangaraj rajkumar-rangaraj
OpenTelemetry.Resources.Azure has an unbounded HTTP response body read Moderate
CVE-2026-41483 was published for OpenTelemetry.Resources.Azure (NuGet) Apr 29, 2026
martincostello Credited to martincostello and Kielek Kielek Kielek
OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure Moderate
CVE-2026-41310 was published for OpenTelemetry.Exporter.Zipkin (NuGet) Apr 28, 2026
Kielek Credited to Kielek, martincostello, and arminru martincostello martincostello
arminru arminru
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path Moderate
CVE-2026-41078 was published for OpenTelemetry.Exporter.Jaeger (NuGet) Apr 18, 2026
Kielek Credited to Kielek and arminru arminru arminru
OpenTelemetry.Sampler.AWS & OpenTelemetry.Resources.AWS have unbounded HTTP response body reads Moderate
CVE-2026-41173 was published for OpenTelemetry.Resources.AWS (NuGet) Apr 23, 2026
Kielek Credited to Kielek, normj, martincostello, and arminru normj normj
martincostello martincostello arminru arminru
Meridian: Multiple defense-in-depth gaps (collection/depth caps, telemetry, retry, fan-out) High
GHSA-f5v8-v6q3-q4h6 was published for Meridian.Mapping (NuGet) Apr 16, 2026
.NET Denial of Service Vulnerability High
CVE-2026-26130 was published for Microsoft.AspNetCore.App.Runtime.linux-arm (NuGet) Mar 11, 2026
ProTip! Advisories are also available from the GraphQL API