GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
74
GitHub Actions
54
Go
4,080
Maven
5,000+
npm
5,000+
NuGet
994
pip
5,000+
Pub
13
RubyGems
1,095
Rust
1,412
Swift
61
Unreviewed advisories
All unreviewed
5,000+
1,807 advisories
Filter by severity
Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)
High
GHSA-v52w-28xh-v562
was published
for
@kozou/api
(npm)
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
CVE-2026-49209
was published
for
symfony/ux-live-component
(Composer)
Jun 19, 2026
undici WebSocket client vulnerable to denial of service via fragment count bypass
High
CVE-2026-12151
was published
for
undici
(npm)
Jun 19, 2026
DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform.
This issue...
High
Unreviewed
CVE-2025-7737
was published
Jun 19, 2026
PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service
High
GHSA-3prj-6hqw-cm82
was published
for
web-token/jwt-framework
(Composer)
Jun 18, 2026
Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated...
Moderate
Unreviewed
CVE-2026-55205
was published
Jun 18, 2026
pypdf: Missing stream length values ignore defined limits
Moderate
GHSA-jm82-fx9c-mx94
was published
for
pypdf
(pip)
Jun 18, 2026
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
High
CVE-2026-9675
was published
for
undici
(npm)
Jun 18, 2026
NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation
Moderate
CVE-2026-55254
was published
for
NCalc.Core
(NuGet)
Jun 18, 2026
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this...
Moderate
Unreviewed
CVE-2026-27869
was published
Jun 17, 2026
pypdf: Manipulated XMP metadata streams can exhaust RAM
Moderate
CVE-2026-48735
was published
for
pypdf
(pip)
Jun 16, 2026
Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
Moderate
CVE-2026-50560
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 15, 2026
Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
High
CVE-2026-50011
was published
for
io.netty:netty-codec-redis
(Maven)
Jun 15, 2026
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
High
CVE-2026-48748
was published
for
io.netty:netty-codec-http3
(Maven)
Jun 15, 2026
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
High
CVE-2026-54283
was published
for
starlette
(pip)
Jun 15, 2026
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
Moderate
CVE-2026-54285
was published
for
@opentelemetry/core
(npm)
Jun 15, 2026
protobufjs: Memory amplification from preserved unknown fields in binary decode
Moderate
CVE-2026-54270
was published
for
protobufjs
(npm)
Jun 15, 2026
aiohttp: Incomplete websocket frame payloads bypass memory limits
Moderate
CVE-2026-54274
was published
for
aiohttp
(pip)
Jun 15, 2026
aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
Moderate
CVE-2026-54273
was published
for
aiohttp
(pip)
Jun 15, 2026
aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
Moderate
CVE-2026-54277
was published
for
aiohttp
(pip)
Jun 15, 2026
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely...
Moderate
Unreviewed
CVE-2026-8683
was published
Jun 15, 2026
ws: Memory exhaustion DoS from tiny fragments and data chunks
High
CVE-2026-48779
was published
for
ws
(npm)
Jun 15, 2026
NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length
Moderate
CVE-2026-28975
was published
for
github.com/apple/swift-nio-extras
(Swift)
Jun 12, 2026
SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS
High
CVE-2026-28980
was published
for
github.com/apple/swift-nio
(Swift)
Jun 12, 2026
Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers...
Moderate
Unreviewed
CVE-2026-53781
was published
Jun 11, 2026
ProTip!
Advisories are also available from the
GraphQL API