Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

41 advisories

Loading
Duplicate Advisory: Scrapy decompression bomb vulnerability High
GHSA-rmqv-7v3j-mr7p was published for scrapy (pip) Apr 16, 2024 withdrawn
Pillow vulnerable to Data Amplification attack. High
CVE-2022-45198 was published for pillow (pip) Nov 14, 2022
Duplicate Advisory: .NET and Visual Studio Denial of Service Vulnerability High
GHSA-wmm6-pgp8-29hg was published for System.Formats.Nrbf (NuGet) Nov 12, 2024 withdrawn
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing High
CVE-2024-7765 was published for ai.h2o:h2o-core (Maven) Mar 20, 2025
.NET Denial of Service Vulnerability High
CVE-2024-43499 was published for System.Formats.Nrbf (NuGet) Nov 12, 2024
yusuke-koyoshi Credited to yusuke-koyoshi
Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter High
CVE-2025-30153 was published for github.com/getkin/kin-openapi (Go) Mar 19, 2025
blotus Credited to blotus and dwertent dwertent dwertent
Chall-Manager's scenario decoding process does not check for zip bombs High
CVE-2025-53633 was published for github.com/ctfer-io/chall-manager (Go) Jul 10, 2025
Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP High
CVE-2024-12886 was published for github.com/ollama/ollama (Go) Mar 20, 2025
urllib3 streaming API improperly handles highly compressed data High
CVE-2025-66471 was published for urllib3 (pip) Dec 5, 2025
illia-v Credited to illia-v, pquentin, sethmlarson, Cycloctane, and stamparm pquentin pquentin
sethmlarson sethmlarson Cycloctane Cycloctane stamparm stamparm
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb High
CVE-2025-69223 was published for aiohttp (pip) Jan 5, 2026
charleswhchan Credited to charleswhchan and bdraco bdraco bdraco
GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS High
CVE-2026-22870 was published for guarddog (pip) Jan 13, 2026
dwBruijn Credited to dwBruijn
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) High
CVE-2026-21441 was published for urllib3 (pip) Jan 7, 2026
D47A Credited to D47A, illia-v, pquentin, and sethmlarson illia-v illia-v
pquentin pquentin sethmlarson sethmlarson
Apollo Router's Compressed Payloads do not respect HTTP Payload Limits High
CVE-2024-28101 was published for apollo-router (Rust) Mar 6, 2024
IvanGoncharov Credited to IvanGoncharov, Geal, peakematt, and sunnypatell Geal Geal
peakematt peakematt sunnypatell sunnypatell
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder High
GHSA-2phg-qgmm-r638 was published for github.com/BishopFox/sliver (Go) Feb 25, 2026
Cycloctane Credited to Cycloctane
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression High
CVE-2026-1526 was published for undici (npm) Mar 13, 2026
HO-9 Credited to HO-9, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Scrapy decompression bomb vulnerability High
CVE-2024-3572 was published for scrapy (pip) Feb 16, 2024
dmandefy Credited to dmandefy
Duplicate Advisory: Unfurl's unbounded zlib decompression allows decompression bomb DoS High
GHSA-c3f2-qg8v-25q2 was published for dfir-unfurl (pip) Apr 9, 2026 withdrawn
Unfurl's unbounded zlib decompression allows decompression bomb DoS High
CVE-2026-40036 was published for dfir-unfurl (pip) Jan 29, 2026
mobasi-team Credited to mobasi-team
cowlib: Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame High
CVE-2026-43970 was published for cowlib (Erlang) May 13, 2026
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload High
CVE-2026-44697 was published for github.com/klever-io/klever-go (Go) May 13, 2026
fbsobreira Credited to fbsobreira
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API High
CVE-2026-44432 was published for urllib3 (pip) May 11, 2026
kimkou2024 Credited to kimkou2024, Cycloctane, illia-v, and pquentin Cycloctane Cycloctane
illia-v illia-v pquentin pquentin
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) High
CVE-2026-49855 was published for tornado (pip) Jun 15, 2026
yuui25 Credited to yuui25
AArnott Credited to AArnott
ProTip! Advisories are also available from the GraphQL API