GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
125 advisories
Filter by severity
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries
High
GHSA-fp43-vj7g-pg92
was published
for
org.omnifaces:omnifaces
(Maven)
Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
High
CVE-2026-73493
was published
for
org.http4s:http4s-blaze-server_2.12
(Maven)
Jul 24, 2026
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
Moderate
CVE-2026-59899
was published
for
io.netty:netty-codec-http
(Maven)
Jul 22, 2026
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
High
GHSA-r7wm-3cxj-wff9
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Jul 21, 2026
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50270
was published
for
com.datadoghq:dd-java-agent
(Maven)
Jul 15, 2026
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
High
CVE-2026-44891
was published
for
io.netty:netty-codec-stomp
(Maven)
Jul 14, 2026
Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
Moderate
CVE-2026-50560
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 15, 2026
Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
High
CVE-2026-50011
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 15, 2026
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
High
CVE-2026-48748
was published
for
io.netty:netty-codec-http3
(Maven)
Jun 15, 2026
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
Moderate
CVE-2026-41726
was published
for
org.springframework.kafka:spring-kafka
(Maven)
Jun 10, 2026
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys
High
CVE-2026-41716
was published
for
org.springframework.data:spring-data-commons
(Maven)
Jun 10, 2026
Spring Framework Denial of Service via Unbounded Cache in SpEL
Moderate
CVE-2026-41851
was published
for
org.springframework:spring-expression
(Maven)
Jun 9, 2026
Spring HATEOAS heap exhaustion through unbounded internal caching
High
CVE-2026-41007
was published
for
org.springframework.hateoas:spring-hateoas
(Maven)
Jun 9, 2026
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
Moderate
CVE-2026-41710
was published
for
org.springframework.retry:spring-retry
(Maven)
Jun 9, 2026
Micrometer HTTP server instrumentations DoS
High
CVE-2026-40984
was published
for
io.micrometer:micrometer-core
(Maven)
Jun 9, 2026
Micrometer gRPC server instrumentation DoS
High
CVE-2026-40983
was published
for
io.micrometer:micrometer-core
(Maven)
Jun 9, 2026
Netty: SCTP reassembly nests buffers without bound
High
CVE-2026-46340
was published
for
io.netty:netty-transport-sctp
(Maven)
Jun 8, 2026
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
High
CVE-2026-45416
was published
for
io.netty:netty-handler
(Maven)
Jun 8, 2026
Spring Cloud Function Context: Uncontrolled Recursion is possible while attempting to add infinite amount of functions to Function Registry
Moderate
CVE-2026-40990
was published
for
org.springframework.cloud:spring-cloud-function-context
(Maven)
Jun 1, 2026
OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation
Moderate
CVE-2026-45292
was published
for
io.opentelemetry:opentelemetry-api
(Maven)
May 14, 2026
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
High
CVE-2026-41284
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 12, 2026
Vert.x has a DoS via unbounded server-side SNI SslContext cache growth
Moderate
CVE-2026-6860
was published
for
io.vertx:vertx-core
(Maven)
May 9, 2026
Netty Lz4FrameDecoder is vulnerable to resource exhaustion
High
CVE-2026-42583
was published
for
io.netty:netty-codec
(Maven)
May 7, 2026
Netty HTTP/3 QPACK literal unbounded allocation
High
CVE-2026-42582
was published
for
io.netty:netty-codec-http3
(Maven)
May 7, 2026
ProTip!
Advisories are also available from the
GraphQL API