GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
3,748 advisories
Filter by severity
vLLM: Speech-to-text upload size limit is enforced after full UploadFile read
Moderate
CVE-2026-55646
was published
for
vllm
(pip)
Jul 17, 2026
Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the...
Moderate
Unreviewed
CVE-2026-9602
was published
Jul 17, 2026
An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the...
High
Unreviewed
CVE-2026-36590
was published
Jul 16, 2026
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files
Moderate
GHSA-xg43-5579-qw6v
was published
for
adawolfa/isdoc
(Composer)
Jul 15, 2026
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
High
CVE-2026-50285
was published
for
github.com/pomerium/pomerium
(Go)
Jul 15, 2026
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50276
was published
for
datadog
(RubyGems)
Jul 15, 2026
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50274
was published
for
github.com/DataDog/dd-trace-go
(Go)
Jul 15, 2026
dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50273
was published
for
Datadog.Trace
(NuGet)
Jul 15, 2026
dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50272
was published
for
dd-trace
(npm)
Jul 15, 2026
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50271
was published
for
ddtrace
(pip)
Jul 15, 2026
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50270
was published
for
com.datadoghq:dd-java-agent
(Maven)
Jul 15, 2026
websocket-driver: Memory exhaustion in HTTP header parser
Moderate
CVE-2026-54465
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
websocket-driver: Memory exhaustion via abuse of protocol length headers
Moderate
CVE-2026-54463
was published
for
websocket-driver
(RubyGems)
Jul 15, 2026
CVE-2026-55399 is a resource exhaustion
vulnerability in the Secure Access publisher prior to 14...
Moderate
Unreviewed
CVE-2026-55399
was published
Jul 15, 2026
CVE-2026-33445 is a memory management
vulnerability in Secure Access servers prior to 14.55....
High
Unreviewed
CVE-2026-33445
was published
Jul 15, 2026
CVE-2026-33443 is a memory management error in
Secure Access servers prior to 14.55. Attackers...
High
Unreviewed
CVE-2026-33443
was published
Jul 15, 2026
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that...
Moderate
Unreviewed
CVE-2026-48357
was published
Jul 15, 2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause...
High
Unreviewed
CVE-2026-47479
was published
Jul 14, 2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause...
High
Unreviewed
CVE-2026-47476
was published
Jul 14, 2026
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting
Moderate
CVE-2026-55512
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
High
CVE-2026-44891
was published
for
io.netty:netty-codec-stomp
(Maven)
Jul 14, 2026
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
High
CVE-2026-54448
was published
for
github.com/aquasecurity/trivy
(Go)
Jul 14, 2026
Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny...
High
Unreviewed
CVE-2026-58627
was published
Jul 14, 2026
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS)...
Moderate
Unreviewed
CVE-2026-49799
was published
Jul 14, 2026
MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion
High
CVE-2026-50125
was published
for
github.com/StacklokLabs/mkp
(Go)
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API