GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
45 advisories
Filter by severity
superagent vulnerable to zip bomb attacks
Moderate
CVE-2017-16129
was published
for
superagent
(npm)
Aug 9, 2018
Data Amplification in HashiCorp go-getter
Moderate
CVE-2023-0475
was published
for
github.com/hashicorp/go-getter
(Go)
Feb 16, 2023
gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
Moderate
CVE-2023-26483
was published
for
github.com/russellhaering/gosaml2
(Go)
Mar 2, 2023
Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)
Moderate
CVE-2024-28180
was published
for
github.com/go-jose/go-jose/v3
(Go)
Mar 7, 2024
A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13...
Moderate
Unreviewed
CVE-2024-1947
was published
May 23, 2024
Mattermost Data Amplification vulnerability
Moderate
CVE-2024-54682
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Dec 16, 2024
IBM PowerVM Hypervisor FW1050.00 through FW1050.30 and FW1060.00 through FW1060.20 could allow a...
Moderate
Unreviewed
CVE-2025-0986
was published
Mar 28, 2025
This vulnerability allows any authenticated user to cause the server to consume very large...
Moderate
Unreviewed
CVE-2025-32949
was published
Apr 15, 2025
Possible DoS by memory exhaustion in net-imap
Moderate
CVE-2025-25186
was published
for
net-imap
(RubyGems)
Feb 10, 2025
IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of...
Moderate
Unreviewed
CVE-2024-55909
was published
May 2, 2025
Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
Moderate
CVE-2025-46730
was published
for
mobsf
(pip)
May 5, 2025
Netty's decoders vulnerable to DoS via zip bomb style attack
Moderate
CVE-2025-58057
was published
for
io.netty:netty-codec
(Maven)
Sep 3, 2025
A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an...
Moderate
Unreviewed
CVE-2024-12387
was published
Mar 20, 2025
pypdf can exhaust RAM via manipulated LZWDecode streams
Moderate
CVE-2025-62708
was published
for
pypdf
(pip)
Oct 22, 2025
ProcessWire CMS vulnerable to resource-exhaustion Denial of Service
Moderate
CVE-2025-60790
was published
for
processwire/processwire
(Composer)
Oct 21, 2025
An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs...
Moderate
Unreviewed
CVE-2025-63914
was published
Nov 24, 2025
pypdf's LZWDecode streams be manipulated to exhaust RAM
Moderate
CVE-2025-66019
was published
for
pypdf
(pip)
Nov 24, 2025
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
nats-server websockets are vulnerable to pre-auth memory DoS
Moderate
CVE-2026-27571
was published
for
github.com/nats-io/nats-server
(Go)
Feb 24, 2026
OpenClaw skills-install-download: tar.bz2 extraction bypassed archive safety parity checks (local DoS)
Moderate
GHSA-77hf-7fqf-f227
was published
for
openclaw
(npm)
Mar 3, 2026
file-type: ZIP Decompression Bomb DoS via [Content_Types].xml entry
Moderate
CVE-2026-32630
was published
for
file-type
(npm)
Mar 13, 2026
Keycloak: Denial of Service due to excessive SAMLRequest decompression
Moderate
CVE-2026-2575
was published
for
org.keycloak:keycloak-saml-adapter-core
(Maven)
Mar 18, 2026
PDFME Affected by Decompression Bomb in FlateDecode Stream Parsing Causes Memory Exhaustion DoS
Moderate
GHSA-vrqm-gvq7-rrwh
was published
for
@pdfme/pdf-lib
(npm)
Mar 20, 2026
OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2...
Moderate
Unreviewed
CVE-2026-32044
was published
Mar 21, 2026
Mattermost doesn't validate decompressed archive entry sizes during file extraction
Moderate
CVE-2026-3114
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API