GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
192 advisories
Filter by severity
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
Moderate
CVE-2026-55407
was published
for
buffa
(Rust)
Aug 28, 2026
openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before...
High
Unreviewed
CVE-2026-81693
was published
Aug 27, 2026
openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit...
High
Unreviewed
CVE-2026-81692
was published
Aug 27, 2026
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
High
CVE-2026-77354
was published
for
github.com/getkin/kin-openapi
(Go)
Aug 21, 2026
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
High
CVE-2026-55149
was published
for
github.com/vouch/vouch-proxy
(Go)
Aug 20, 2026
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation
High
CVE-2026-69219
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small...
Moderate
Unreviewed
CVE-2026-72687
was published
Aug 13, 2026
Elasticsearch does not validate a size value taken from a user-supplied input before that value...
Moderate
Unreviewed
CVE-2026-72678
was published
Aug 13, 2026
Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of...
Moderate
Unreviewed
CVE-2026-72656
was published
Aug 13, 2026
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of...
Moderate
Unreviewed
CVE-2026-72645
was published
Aug 13, 2026
Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search...
Moderate
Unreviewed
CVE-2026-72639
was published
Aug 13, 2026
A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the ...
Moderate
Unreviewed
CVE-2026-71218
was published
Aug 11, 2026
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as...
High
Unreviewed
CVE-2026-15567
was published
Aug 11, 2026
GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src...
Moderate
Unreviewed
CVE-2026-66485
was published
Aug 10, 2026
Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in...
High
Unreviewed
CVE-2026-66733
was published
Aug 6, 2026
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
High
CVE-2026-71314
was published
for
nuxt
(npm)
Aug 5, 2026
imagecli's `scale <ratio>` pipeline operation (Scale::apply() in src/image_ops.rs) computes...
High
Unreviewed
CVE-2026-70377
was published
Aug 5, 2026
** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in...
High
Unreviewed
CVE-2026-61485
was published
Aug 5, 2026
pre-authentication attacker could leverage type size/count handling to cause excessive allocation...
High
Unreviewed
CVE-2026-67551
was published
Aug 5, 2026
A pre-authentication attacker could leverage type size/count handling to cause excessive...
High
Unreviewed
CVE-2026-66273
was published
Aug 5, 2026
A pre-authentication attacker could leverage type size/count handling to cause excessive...
High
Unreviewed
CVE-2026-67589
was published
Aug 5, 2026
SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that...
High
Unreviewed
CVE-2026-69702
was published
Aug 4, 2026
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.utils...
Moderate
Unreviewed
CVE-2026-15337
was published
Aug 4, 2026
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust...
High
Unreviewed
CVE-2026-58067
was published
Aug 4, 2026
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length...
High
Unreviewed
CVE-2026-12852
was published
Aug 3, 2026
ProTip!
Advisories are also available from the
GraphQL API