GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,193
Erlang
25
GitHub Actions
39
Go
2,385
Maven
3,027
npm
3,078
NuGet
529
pip
2,897
Pub
5
RubyGems
442
Rust
905
Swift
20
Unreviewed advisories
All unreviewed
5,000+
78 advisories
Filter by severity
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
Moderate
GHSA-x284-j5p8-9c5p
was published
for
pypdf
(pip)
Apr 16, 2026
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
Moderate
GHSA-7gw9-cf7v-778f
was published
for
pypdf
(pip)
Apr 16, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
High
CVE-2026-40303
was published
for
github.com/openziti/zrok
(Go)
Apr 16, 2026
Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend
Moderate
CVE-2026-35186
was published
for
wasmtime
(Rust)
Apr 10, 2026
Duplicate Advisory: OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure
Moderate
GHSA-hm63-vwj4-mj2q
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64
Moderate
CVE-2026-34944
was published
for
wasmtime
(Rust)
Apr 9, 2026
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
Moderate
CVE-2026-39882
was published
for
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp
(Go)
Apr 8, 2026
NVIDIA Triton Inference Server contains a vulnerability where insufficient input validation and a...
High
Unreviewed
CVE-2026-24146
was published
Apr 7, 2026
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6,...
Moderate
Unreviewed
CVE-2026-35549
was published
Apr 3, 2026
An attacker might be able to trick DNSdist into allocating too much memory while processing DNS...
Moderate
Unreviewed
CVE-2026-24030
was published
Mar 31, 2026
NVIDIA Triton Inference Server contains a vulnerability in the HTTP endpoint where an attacker...
High
Unreviewed
CVE-2026-24158
was published
Mar 24, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Moderate
CVE-2026-33174
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service
Moderate
CVE-2026-26931
was published
for
github.com/elastic/beats/v7
(Go)
Mar 19, 2026
dr_libs version 0.13.3 and earlier contain an uncontrolled memory allocation vulnerability in...
Moderate
Unreviewed
CVE-2026-32836
was published
Mar 17, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports
Moderate
CVE-2026-32941
was published
for
github.com/bishopfox/sliver
(Go)
Mar 17, 2026
Mattermost fails to limit the size of responses from integration action endpoints
Moderate
CVE-2026-2456
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost fails to bound memory allocation when processing DOC files
Moderate
CVE-2026-25780
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost fails to bound memory allocation when processing PSD image files
Moderate
CVE-2026-26246
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and...
High
Unreviewed
CVE-2026-28253
was published
Mar 12, 2026
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000...
High
Unreviewed
CVE-2026-20048
was published
Feb 25, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation
High
CVE-2026-25899
was published
for
github.com/gofiber/fiber/v3
(Go)
Feb 24, 2026
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
Moderate
CVE-2026-27204
was published
for
wasmtime
(Rust)
Feb 24, 2026
ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder
High
CVE-2026-25985
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
EVE Freely Allocates Buffer on The Stack With Data From Socket
Moderate
CVE-2023-43632
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
ProTip!
Advisories are also available from the
GraphQL API