GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,798
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
369 advisories
Filter by severity
AnyIO process-pool workers can block indefinitely on undrained stderr
Moderate
CVE-2026-64847
was published
for
anyio
(pip)
Sep 18, 2026
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
Moderate
CVE-2026-77281
was published
for
github.com/caddyserver/caddy/v2
(Go)
Sep 18, 2026
Svelte devalue: DoS via malformed input
Moderate
CVE-2026-81176
was published
for
devalue
(npm)
Sep 17, 2026
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Moderate
CVE-2026-69147
was published
for
vllm
(pip)
Sep 17, 2026
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
Moderate
CVE-2026-57173
was published
for
vllm
(pip)
Sep 16, 2026
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
Moderate
CVE-2026-88012
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
Moderate
CVE-2026-71486
was published
for
vllm
(pip)
Sep 4, 2026
qs array-limit bypass via bracket-key comma parsing
Moderate
CVE-2026-82562
was published
for
qs
(npm)
Sep 2, 2026
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
Moderate
GHSA-8423-8fgw-73vq
was published
for
tornado
(pip)
Sep 1, 2026
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
Moderate
CVE-2026-73228
was published
for
djangorestframework
(pip)
Sep 1, 2026
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
Moderate
CVE-2026-55407
was published
for
buffa
(Rust)
Aug 28, 2026
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
Moderate
CVE-2026-55619
was published
for
eml_parser
(pip)
Aug 25, 2026
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
Moderate
CVE-2026-55531
was published
for
PraisonAI
(pip)
Aug 25, 2026
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
Moderate
GHSA-fx4f-mhw4-qm7j
was published
for
vibeio-http
(Rust)
Aug 24, 2026
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
Moderate
CVE-2026-67447
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
Moderate
GHSA-jgvr-6x5w-hx5w
was published
for
kcl-lib
(pip)
Aug 20, 2026
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
Moderate
CVE-2026-53941
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
Aug 19, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Moderate
CVE-2026-53423
was published
for
membrane_mp4_plugin
(Erlang)
Aug 18, 2026
s2n-quic has excessive memory allocation
Moderate
CVE-2026-10740
was published
for
s2n-quic
(Rust)
Aug 14, 2026
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
Moderate
CVE-2026-12570
was published
for
keras
(pip)
Aug 10, 2026
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
Moderate
CVE-2026-71310
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
Duplicate Advisory: jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
Moderate
GHSA-6qm2-mcq7-53qp
was published
for
tools.jackson.core:jackson-core
(Maven)
Aug 4, 2026
•
withdrawn
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
Moderate
GHSA-3fvr-2jw6-crq4
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
Moderate
GHSA-39j5-w47m-2gmv
was published
for
axios
(npm)
Aug 1, 2026
•
withdrawn
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
Moderate
GHSA-3whf-vgf2-9w6g
was published
for
zaino-state
(Rust)
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API