Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

369 advisories

Loading
AnyIO process-pool workers can block indefinitely on undrained stderr Moderate
CVE-2026-64847 was published for anyio (pip) Sep 18, 2026
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass Moderate
CVE-2026-77281 was published for github.com/caddyserver/caddy/v2 (Go) Sep 18, 2026
WhiskerEnt Credited to WhiskerEnt
Svelte devalue: DoS via malformed input Moderate
CVE-2026-81176 was published for devalue (npm) Sep 17, 2026
Rich-Harris Credited to Rich-Harris, kq5y, and elliott-with-the-longest-name-on-github kq5y kq5y
elliott-with-the-longest-name-on-github elliott-with-the-longest-name-on-github
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation Moderate
CVE-2026-69147 was published for vllm (pip) Sep 17, 2026
rexpository Credited to rexpository and jperezdealgaba jperezdealgaba jperezdealgaba
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions Moderate
CVE-2026-57173 was published for vllm (pip) Sep 16, 2026
koonnamchok Credited to koonnamchok, DarkLight1337, and jperezdealgaba DarkLight1337 DarkLight1337
jperezdealgaba jperezdealgaba
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded Moderate
CVE-2026-88012 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
ShadMalloy Credited to ShadMalloy
rexpository Credited to rexpository and jperezdealgaba jperezdealgaba jperezdealgaba
qs array-limit bypass via bracket-key comma parsing Moderate
CVE-2026-82562 was published for qs (npm) Sep 2, 2026
Vectrain51 Credited to Vectrain51, Fcmam5, and ljharb Fcmam5 Fcmam5
ljharb ljharb
p80n-sec Credited to p80n-sec
eml_parser has parser DoS via deeply nested parentheses in e-mail headers Moderate
CVE-2026-55619 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
geo-chen Credited to geo-chen
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement Moderate
CVE-2026-67447 was published for github.com/axllent/mailpit (Go) Aug 20, 2026
rexpository Credited to rexpository
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service Moderate
GHSA-jgvr-6x5w-hx5w was published for kcl-lib (pip) Aug 20, 2026
maxammann Credited to maxammann
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS Moderate
CVE-2026-53941 was published for github.com/inspektor-gadget/inspektor-gadget (Go) Aug 19, 2026
alban Credited to alban, eiffel-fl, and mauriciovasquezbernal eiffel-fl eiffel-fl
mauriciovasquezbernal mauriciovasquezbernal
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion Moderate
CVE-2026-53423 was published for membrane_mp4_plugin (Erlang) Aug 18, 2026
varsill Credited to varsill, mat-hek, and maennchen mat-hek mat-hek
maennchen maennchen
s2n-quic has excessive memory allocation Moderate
CVE-2026-10740 was published for s2n-quic (Rust) Aug 14, 2026
Keras model loading is vulnerable to denial of service through HDF5 shape bombs Moderate
CVE-2026-12570 was published for keras (pip) Aug 10, 2026
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory Moderate
CVE-2026-71310 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r, ncw, and 0x0sky ncw ncw
0x0sky 0x0sky
Duplicate Advisory: jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition Moderate
GHSA-6qm2-mcq7-53qp was published for tools.jackson.core:jackson-core (Maven) Aug 4, 2026 withdrawn
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service Moderate
GHSA-3fvr-2jw6-crq4 was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Duplicate Advisory: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` Moderate
GHSA-39j5-w47m-2gmv was published for axios (npm) Aug 1, 2026 withdrawn
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit Moderate
GHSA-3whf-vgf2-9w6g was published for zaino-state (Rust) Jul 31, 2026
ouicate Credited to ouicate
ProTip! Advisories are also available from the GraphQL API