Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

125 advisories

Loading
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding High
CVE-2026-54609 was published for com.quietterminal:qti-neon (Maven) Jul 28, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server High
CVE-2026-73493 was published for org.http4s:http4s-blaze-server_2.12 (Maven) Jul 24, 2026
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service Moderate
CVE-2026-59899 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) High
GHSA-r7wm-3cxj-wff9 was published for com.fasterxml.jackson.core:jackson-core (Maven) Jul 21, 2026
tonghuaroot Credited to tonghuaroot, pjfanning, and cowtowncoder pjfanning pjfanning
cowtowncoder cowtowncoder
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS High
CVE-2026-50270 was published for com.datadoghq:dd-java-agent (Maven) Jul 15, 2026
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder High
CVE-2026-44891 was published for io.netty:netty-codec-stomp (Maven) Jul 14, 2026
violetagg Credited to violetagg
Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature Moderate
CVE-2026-50560 was published for io.netty:netty-codec-http2 (Maven) Jun 15, 2026
ashleytolbert Credited to ashleytolbert
Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length High
CVE-2026-50011 was published for io.netty:netty-codec-redis (Maven) Jun 15, 2026
violetagg Credited to violetagg
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion High
CVE-2026-48748 was published for io.netty:netty-codec-http3 (Maven) Jun 15, 2026
violetagg Credited to violetagg and julianladisch julianladisch julianladisch
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header Moderate
CVE-2026-41726 was published for org.springframework.kafka:spring-kafka (Maven) Jun 10, 2026
julianladisch Credited to julianladisch
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys High
CVE-2026-41716 was published for org.springframework.data:spring-data-commons (Maven) Jun 10, 2026
Spring Framework Denial of Service via Unbounded Cache in SpEL Moderate
CVE-2026-41851 was published for org.springframework:spring-expression (Maven) Jun 9, 2026
Spring HATEOAS heap exhaustion through unbounded internal caching High
CVE-2026-41007 was published for org.springframework.hateoas:spring-hateoas (Maven) Jun 9, 2026
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service Moderate
CVE-2026-41710 was published for org.springframework.retry:spring-retry (Maven) Jun 9, 2026
Micrometer HTTP server instrumentations DoS High
CVE-2026-40984 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Micrometer gRPC server instrumentation DoS High
CVE-2026-40983 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Netty: SCTP reassembly nests buffers without bound High
CVE-2026-46340 was published for io.netty:netty-transport-sctp (Maven) Jun 8, 2026
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes High
CVE-2026-45416 was published for io.netty:netty-handler (Maven) Jun 8, 2026
Spring Cloud Function Context: Uncontrolled Recursion is possible while attempting to add infinite amount of functions to Function Registry Moderate
CVE-2026-40990 was published for org.springframework.cloud:spring-cloud-function-context (Maven) Jun 1, 2026
OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation Moderate
CVE-2026-45292 was published for io.opentelemetry:opentelemetry-api (Maven) May 14, 2026
August829 Credited to August829, trask, and jack-berg trask trask
jack-berg jack-berg
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling High
CVE-2026-41284 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) May 12, 2026
Vert.x has a DoS via unbounded server-side SNI SslContext cache growth Moderate
CVE-2026-6860 was published for io.vertx:vertx-core (Maven) May 9, 2026
shblue21 Credited to shblue21, Preethi-30, and julianladisch Preethi-30 Preethi-30
julianladisch julianladisch
Netty Lz4FrameDecoder is vulnerable to resource exhaustion High
CVE-2026-42583 was published for io.netty:netty-codec (Maven) May 7, 2026
violetagg Credited to violetagg
Netty HTTP/3 QPACK literal unbounded allocation High
CVE-2026-42582 was published for io.netty:netty-codec-http3 (Maven) May 7, 2026
violetagg Credited to violetagg, nicolaideffremo, normanmaurer, and massif-01 nicolaideffremo nicolaideffremo
normanmaurer normanmaurer massif-01 massif-01
ProTip! Advisories are also available from the GraphQL API