GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
49 advisories
Filter by severity
ffuf denial of service (OOM) via HTTP response decompression bomb
High
CVE-2026-73232
was published
for
github.com/ffuf/ffuf
(Go)
Sep 3, 2026
pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the...
High
Unreviewed
CVE-2026-82864
was published
Aug 31, 2026
LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write....
High
Unreviewed
CVE-2026-80189
was published
Aug 26, 2026
http4s has HTTP/2 Denial of Service with Ember Backend
High
CVE-2026-54556
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Aug 26, 2026
gRPC Erlang package has unbounded gzip decompression (decompression bomb)
High
CVE-2026-53430
was published
for
grpc
(Erlang)
Aug 25, 2026
exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory...
High
Unreviewed
CVE-2026-78206
was published
Aug 24, 2026
Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting...
High
Unreviewed
CVE-2026-19671
was published
Aug 18, 2026
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
High
CVE-2026-53659
was published
for
org.http4k:http4k-core
(Maven)
Aug 17, 2026
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API...
High
Unreviewed
CVE-2026-68981
was published
Aug 3, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
CVE-2026-49755
was published
for
req
(Erlang)
Jul 29, 2026
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C...
High
Unreviewed
CVE-2026-48586
was published
Jul 27, 2026
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift...
High
Unreviewed
CVE-2026-49158
was published
Jul 27, 2026
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
High
CVE-2026-41608
was published
for
thrift
(pip)
Jul 27, 2026
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
High
CVE-2026-59939
was published
for
httplib2
(pip)
Jul 24, 2026
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
High
CVE-2026-59932
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
High
CVE-2026-56755
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The...
High
Unreviewed
CVE-2026-61449
was published
Jul 15, 2026
A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate...
High
Unreviewed
CVE-2026-15709
was published
Jul 14, 2026
Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that...
High
Unreviewed
CVE-2026-61455
was published
Jul 10, 2026
Tesla has decompression bomb on response body
High
CVE-2026-48594
was published
for
tesla
(Erlang)
Jul 10, 2026
rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in...
High
Unreviewed
CVE-2026-59803
was published
Jul 8, 2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause...
High
Unreviewed
CVE-2026-24264
was published
Jul 1, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
High
CVE-2026-44160
was published
for
fluentd
(RubyGems)
Jun 26, 2026
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
High
CVE-2026-48502
was published
for
MessagePack
(NuGet)
Jun 25, 2026
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
High
CVE-2026-49855
was published
for
tornado
(pip)
Jun 15, 2026
ProTip!
Advisories are also available from the
GraphQL API