Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

104 advisories

Loading
ffuf denial of service (OOM) via HTTP response decompression bomb High
CVE-2026-73232 was published for github.com/ffuf/ffuf (Go) Sep 3, 2026
Tricta Credited to Tricta
Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits Moderate
CVE-2026-61690 was published for getgrav/grav (Composer) Sep 2, 2026
alienkeric Credited to alienkeric
MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS Moderate
GHSA-rgwj-5xj2-c3m3 was published for mysql2 (npm) Aug 31, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
http4s has HTTP/2 Denial of Service with Ember Backend High
CVE-2026-54556 was published for org.http4s:http4s-ember-core_2.12 (Maven) Aug 26, 2026
reardonj Credited to reardonj and rossabaker rossabaker rossabaker
gRPC Erlang package has unbounded gzip decompression (decompression bomb) High
CVE-2026-53430 was published for grpc (Erlang) Aug 25, 2026
PJUllrich Credited to PJUllrich and polvalente polvalente polvalente
Tanium addressed a compression bomb vulnerability in Threat Response. Low Unreviewed
CVE-2026-75476 was published Aug 19, 2026
Tanium addressed a compression bomb vulnerability in Findings. Low Unreviewed
CVE-2026-11617 was published Aug 19, 2026
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS High
CVE-2026-53659 was published for org.http4k:http4k-core (Maven) Aug 17, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type High
CVE-2026-49755 was published for req (Erlang) Jul 29, 2026
PJUllrich Credited to PJUllrich and maennchen maennchen maennchen
carlosfunk Credited to carlosfunk and oscerd oscerd oscerd
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server Moderate
CVE-2026-55497 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
riodrwn Credited to riodrwn
ProTip! Advisories are also available from the GraphQL API