GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,948
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,383
Swift
56
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
Bandit: Unauthenticated DoS via chunked request trailers in Bandit HTTP/1 decoder
High
CVE-2026-39806
was published
for
bandit
(Erlang)
May 19, 2026
Bandit: Unauthenticated one-shot DoS via `Transfer-Encoding: chunked`
High
CVE-2026-39803
was published
for
bandit
(Erlang)
May 19, 2026
Postgrex: Channel-name SQL injection in `Postgrex.Notifications.listen/3`
High
CVE-2026-32687
was published
for
postgrex
(Erlang)
May 18, 2026
Absinthe: Quadratic fragment-name uniqueness check
High
CVE-2026-43967
was published
for
absinthe
(Erlang)
May 14, 2026
Absinthe: Unbounded atom creation from parsed directive name
High
CVE-2026-42793
was published
for
absinthe
(Erlang)
May 14, 2026
Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS
Moderate
CVE-2026-32686
was published
for
decimal
(Erlang)
May 12, 2026
Phoenix: Long-poll NDJSON body splitting causes large memory allocation
High
CVE-2026-32689
was published
for
phoenix
(Erlang)
May 8, 2026
Bandit HTTP/2 Frame Size Limit Bypass via Late Buffer Check Enables Memory Exhaustion
Moderate
CVE-2026-42788
was published
for
bandit
(Erlang)
May 7, 2026
Bandit trusts client-supplied URI scheme on plaintext connections
Moderate
CVE-2026-39807
was published
for
bandit
(Erlang)
May 7, 2026
Bandit is vulnerable to CL.CL request smuggling via unrejected duplicate `Content-Length` header
Moderate
CVE-2026-39805
was published
for
bandit
(Erlang)
May 7, 2026
Bandit Buffers Unbounded WebSocket Continuation Frames, Allowing Unauthenticated Memory Exhaustion
High
CVE-2026-42786
was published
for
bandit
(Erlang)
May 7, 2026
Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame
High
CVE-2026-39804
was published
for
bandit
(Erlang)
May 7, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
CVE-2026-32688
was published
for
plug_cowboy
(Erlang)
May 5, 2026
ProTip!
Advisories are also available from the
GraphQL API