GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
41 advisories
Filter by severity
Duplicate Advisory: Scrapy decompression bomb vulnerability
High
GHSA-rmqv-7v3j-mr7p
was published
for
scrapy
(pip)
Apr 16, 2024
•
withdrawn
Pillow vulnerable to Data Amplification attack.
High
CVE-2022-45198
was published
for
pillow
(pip)
Nov 14, 2022
Duplicate Advisory: .NET and Visual Studio Denial of Service Vulnerability
High
GHSA-wmm6-pgp8-29hg
was published
for
System.Formats.Nrbf
(NuGet)
Nov 12, 2024
•
withdrawn
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
High
CVE-2024-7765
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
.NET Denial of Service Vulnerability
High
CVE-2024-43499
was published
for
System.Formats.Nrbf
(NuGet)
Nov 12, 2024
Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter
High
CVE-2025-30153
was published
for
github.com/getkin/kin-openapi
(Go)
Mar 19, 2025
Chall-Manager's scenario decoding process does not check for zip bombs
High
CVE-2025-53633
was published
for
github.com/ctfer-io/chall-manager
(Go)
Jul 10, 2025
Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP
High
CVE-2024-12886
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
urllib3 streaming API improperly handles highly compressed data
High
CVE-2025-66471
was published
for
urllib3
(pip)
Dec 5, 2025
Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial...
High
Unreviewed
CVE-2025-66909
was published
Dec 19, 2025
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
High
CVE-2025-69223
was published
for
aiohttp
(pip)
Jan 5, 2026
GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS
High
CVE-2026-22870
was published
for
guarddog
(pip)
Jan 13, 2026
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
High
CVE-2026-21441
was published
for
urllib3
(pip)
Jan 7, 2026
Apollo Router's Compressed Payloads do not respect HTTP Payload Limits
High
CVE-2024-28101
was published
for
apollo-router
(Rust)
Mar 6, 2024
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder
High
GHSA-2phg-qgmm-r638
was published
for
github.com/BishopFox/sliver
(Go)
Feb 25, 2026
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
High
CVE-2026-1526
was published
for
undici
(npm)
Mar 13, 2026
Scrapy decompression bomb vulnerability
High
CVE-2024-3572
was published
for
scrapy
(pip)
Feb 16, 2024
Duplicate Advisory: Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
GHSA-c3f2-qg8v-25q2
was published
for
dfir-unfurl
(pip)
Apr 9, 2026
•
withdrawn
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
CVE-2026-40036
was published
for
dfir-unfurl
(pip)
Jan 29, 2026
cowlib: Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
High
CVE-2026-43970
was published
for
cowlib
(Erlang)
May 13, 2026
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload
High
CVE-2026-44697
was published
for
github.com/klever-io/klever-go
(Go)
May 13, 2026
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
High
CVE-2026-44432
was published
for
urllib3
(pip)
May 11, 2026
Protocol::HTTP2 versions through 1.12 for Perl is vulnerable to a HTTP/2 Bomb.
Protocol::HTTP2's...
High
Unreviewed
CVE-2026-10725
was published
Jun 6, 2026
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
High
CVE-2026-49855
was published
for
tornado
(pip)
Jun 15, 2026
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
High
CVE-2026-48502
was published
for
MessagePack
(NuGet)
Jun 25, 2026
ProTip!
Advisories are also available from the
GraphQL API