GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
3,868 advisories
Filter by severity
axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing...
Moderate
Unreviewed
CVE-2026-67313
was published
Aug 1, 2026
axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled...
Moderate
Unreviewed
CVE-2026-67312
was published
Aug 1, 2026
axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit...
Moderate
Unreviewed
CVE-2026-67318
was published
Aug 1, 2026
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
High
CVE-2026-53505
was published
for
thumbor
(pip)
Jul 31, 2026
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
High
CVE-2026-53504
was published
for
thumbor
(pip)
Jul 31, 2026
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
High
CVE-2026-56819
was published
for
io.netty:netty-codec-http2
(Maven)
Jul 31, 2026
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
High
CVE-2026-41695
was published
for
org.springframework.data:spring-data-commons
(Maven)
Jul 31, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Moderate
CVE-2026-52857
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon...
High
Unreviewed
CVE-2026-18358
was published
Jul 31, 2026
IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running...
Moderate
Unreviewed
CVE-2026-10695
was published
Jul 30, 2026
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and...
High
Unreviewed
CVE-2024-25039
was published
Jul 30, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0...
High
Unreviewed
CVE-2026-9322
was published
Jul 30, 2026
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
Moderate
CVE-2026-63119
was published
for
mcp
(RubyGems)
Jul 30, 2026
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
High
CVE-2026-67437
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
Moderate
CVE-2026-54712
was published
for
io.opentelemetry.javaagent:opentelemetry-javaagent
(Maven)
Jul 29, 2026
The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per...
High
Unreviewed
CVE-2026-58182
was published
Jul 29, 2026
Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses,...
High
Unreviewed
CVE-2026-65324
was published
Jul 29, 2026
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing...
High
Unreviewed
CVE-2026-58151
was published
Jul 29, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0...
High
Unreviewed
CVE-2026-14981
was published
Jul 28, 2026
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This...
High
Unreviewed
CVE-2026-66299
was published
Jul 28, 2026
Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph...
High
Unreviewed
CVE-2026-66920
was published
Jul 28, 2026
Addressing certain issues, in particular related to operations which may
take excessively long...
High
Unreviewed
CVE-2026-42493
was published
Jul 28, 2026
An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via...
High
Unreviewed
CVE-2025-63913
was published
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API