GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
87 advisories
Filter by severity
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22...
Moderate
Unreviewed
CVE-2026-14298
was published
Aug 13, 2026
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API...
High
Unreviewed
CVE-2026-68981
was published
Aug 3, 2026
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads...
High
Unreviewed
CVE-2026-49975
was published
Jun 8, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
CVE-2026-49755
was published
for
req
(Erlang)
Jul 29, 2026
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C...
High
Unreviewed
CVE-2026-48586
was published
Jul 27, 2026
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift...
High
Unreviewed
CVE-2026-41608
was published
Jul 27, 2026
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4...
Moderate
Unreviewed
CVE-2026-10819
was published
Jul 27, 2026
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift...
High
Unreviewed
CVE-2026-49158
was published
Jul 27, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Moderate
CVE-2026-55497
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
High
CVE-2026-59939
was published
for
httplib2
(pip)
Jul 24, 2026
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
High
CVE-2026-59932
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
High
CVE-2026-56755
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
Moderate
CVE-2026-44018
was published
for
docling
(pip)
Jun 3, 2026
n8n: Denial of Service via ZIP decompression in webhook workflow
Moderate
CVE-2026-54314
was published
for
n8n
(npm)
Jun 16, 2026
ExifReader is vulnerable to denial of service via unbounded decompression of image metadata
Moderate
CVE-2026-8814
was published
for
exifreader
(npm)
May 29, 2026
vLLM: OOM Denial of Service via Audio Decompression Bomb
Moderate
CVE-2026-54233
was published
for
vllm
(pip)
Jun 17, 2026
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files
Moderate
GHSA-xg43-5579-qw6v
was published
for
adawolfa/isdoc
(Composer)
Jul 15, 2026
Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The...
High
Unreviewed
CVE-2026-61449
was published
Jul 15, 2026
A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate...
High
Unreviewed
CVE-2026-15709
was published
Jul 14, 2026
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data...
Moderate
Unreviewed
CVE-2026-12588
was published
Jul 14, 2026
CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources
Moderate
GHSA-9mqm-qcwf-5qhg
was published
for
credsweeper
(pip)
Jul 10, 2026
Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that...
High
Unreviewed
CVE-2026-61455
was published
Jul 10, 2026
Tesla has decompression bomb on response body
High
CVE-2026-48594
was published
for
tesla
(Erlang)
Jul 10, 2026
rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in...
High
Unreviewed
CVE-2026-59803
was published
Jul 8, 2026
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
Moderate
CVE-2026-55078
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
ProTip!
Advisories are also available from the
GraphQL API