GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
65 advisories
Filter by severity
superagent vulnerable to zip bomb attacks
Moderate
CVE-2017-16129
was published
for
superagent
(npm)
Aug 9, 2018
Pillow vulnerable to Data Amplification attack.
High
CVE-2022-45198
was published
for
pillow
(pip)
Nov 14, 2022
Data Amplification in HashiCorp go-getter
Moderate
CVE-2023-0475
was published
for
github.com/hashicorp/go-getter
(Go)
Feb 16, 2023
gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
Moderate
CVE-2023-26483
was published
for
github.com/russellhaering/gosaml2
(Go)
Mar 2, 2023
Scrapy decompression bomb vulnerability
High
CVE-2024-3572
was published
for
scrapy
(pip)
Feb 16, 2024
Apollo Router's Compressed Payloads do not respect HTTP Payload Limits
High
CVE-2024-28101
was published
for
apollo-router
(Rust)
Mar 6, 2024
Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)
Moderate
CVE-2024-28180
was published
for
github.com/go-jose/go-jose/v3
(Go)
Mar 7, 2024
Duplicate Advisory: Scrapy decompression bomb vulnerability
High
GHSA-rmqv-7v3j-mr7p
was published
for
scrapy
(pip)
Apr 16, 2024
•
withdrawn
Duplicate Advisory: .NET and Visual Studio Denial of Service Vulnerability
High
GHSA-wmm6-pgp8-29hg
was published
for
System.Formats.Nrbf
(NuGet)
Nov 12, 2024
•
withdrawn
.NET Denial of Service Vulnerability
High
CVE-2024-43499
was published
for
System.Formats.Nrbf
(NuGet)
Nov 12, 2024
Mattermost Data Amplification vulnerability
Moderate
CVE-2024-54682
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Dec 16, 2024
Possible DoS by memory exhaustion in net-imap
Moderate
CVE-2025-25186
was published
for
net-imap
(RubyGems)
Feb 10, 2025
Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter
High
CVE-2025-30153
was published
for
github.com/getkin/kin-openapi
(Go)
Mar 19, 2025
Apache Seata Vulnerable to Data Amplification
Low
CVE-2024-54016
was published
for
org.apache.seata:seata-parent
(Maven)
Mar 20, 2025
Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP
High
CVE-2024-12886
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
High
CVE-2024-7765
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
Moderate
CVE-2025-46730
was published
for
mobsf
(pip)
May 5, 2025
Chall-Manager's scenario decoding process does not check for zip bombs
High
CVE-2025-53633
was published
for
github.com/ctfer-io/chall-manager
(Go)
Jul 10, 2025
Netty's decoders vulnerable to DoS via zip bomb style attack
Moderate
CVE-2025-58057
was published
for
io.netty:netty-codec
(Maven)
Sep 3, 2025
ProcessWire CMS vulnerable to resource-exhaustion Denial of Service
Moderate
CVE-2025-60790
was published
for
processwire/processwire
(Composer)
Oct 21, 2025
pypdf can exhaust RAM via manipulated LZWDecode streams
Moderate
CVE-2025-62708
was published
for
pypdf
(pip)
Oct 22, 2025
pypdf's LZWDecode streams be manipulated to exhaust RAM
Moderate
CVE-2025-66019
was published
for
pypdf
(pip)
Nov 24, 2025
urllib3 streaming API improperly handles highly compressed data
High
CVE-2025-66471
was published
for
urllib3
(pip)
Dec 5, 2025
Duplicate Advisory: python-jose denial of service via compressed JWE content
Moderate
CVE-2024-29370
was published
for
python-jose
(pip)
Dec 17, 2025
•
withdrawn
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
High
CVE-2025-69223
was published
for
aiohttp
(pip)
Jan 5, 2026
ProTip!
Advisories are also available from the
GraphQL API