Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

748 advisories

Loading
libp2p: yamux connection DoS via oversized data frame High
GHSA-hmj8-5xmh-5573 was published for libp2p (pip) Jul 24, 2026
tahaafarooq Credited to tahaafarooq
Shescape: Quadratic-time denial of service in the flag-protection High
GHSA-gm3r-q2wp-hw87 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash High
CVE-2026-14257 was published for brace-expansion (npm) Jul 24, 2026
bnbdr Credited to bnbdr
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion High
GHSA-g5vv-q72c-7j78 was published for @anephenix/hub (npm) Jul 24, 2026
react-server-dom: Denial of Service in Server Functions High
CVE-2026-44907 was published for react-server-dom-parcel (npm) Jul 24, 2026
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion High
GHSA-v74w-7mr3-4qg3 was published for io.netty:netty-codec-xml (Maven) Jul 24, 2026
violetagg Credited to violetagg
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling High
CVE-2026-59939 was published for httplib2 (pip) Jul 24, 2026
mauriceng98 Credited to mauriceng98
React Router: Unauthenticated Denial of Service via Inefficient Route Matching High
CVE-2026-55685 was published for react-router (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
pypdf: Possible infinite loop for not terminated inline images High
CVE-2026-59936 was published for pypdf (pip) Jul 23, 2026
koltiradw Credited to koltiradw and stefan6419846 stefan6419846 stefan6419846
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion High
CVE-2026-59933 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion High
CVE-2026-59932 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests High
CVE-2024-7708 was published for org.eclipse.jetty:jetty-server (Maven) Jul 22, 2026
kimmerin Credited to kimmerin and pmneo pmneo pmneo
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types High
CVE-2026-56816 was published for io.netty:netty-codec-http3 (Maven) Jul 22, 2026
violetagg Credited to violetagg
Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion High
CVE-2026-56745 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion High
CVE-2026-55851 was published for io.netty:netty-codec-haproxy (Maven) Jul 22, 2026
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation High
CVE-2026-55833 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
Alexender676 Credited to Alexender676
Netty SPDY SETTINGS frame count materializes unbounded settings map High
CVE-2026-55831 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
Alexender676 Credited to Alexender676
pyasn1: Uncontrolled resource consumption when converting decoded REAL values High
CVE-2026-59886 was published for pyasn1 (pip) Jul 21, 2026
gvozdila Credited to gvozdila
tynus2 Credited to tynus2
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs High
CVE-2026-59884 was published for pyssn1 (pip) Jul 21, 2026
mikeappsec Credited to mikeappsec
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set High
CVE-2026-59880 was published for immutable (npm) Jul 21, 2026
nvth Credited to nvth
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS High
CVE-2026-59879 was published for immutable (npm) Jul 21, 2026
mateuszismyname Credited to mateuszismyname
pyasn1 has a DoS vulnerability in decoder High
CVE-2026-23490 was published for pyasn1 (pip) Jan 16, 2026
tsigouris007 Credited to tsigouris007
Docling: Unsafe URI and Path Handling in HTML Backend High
CVE-2026-47214 was published for docling (pip) Jun 3, 2026
brodmart Credited to brodmart
File Browser has a DoS Vulnerability via Public Login API High
CVE-2026-54092 was published for github.com/filebrowser/filebrowser (Go) Jun 12, 2026
AshrafIbrahim03 Credited to AshrafIbrahim03
ProTip! Advisories are also available from the GraphQL API