GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,669
Erlang
34
GitHub Actions
26
Go
2,261
Maven
5,000+
npm
3,910
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
240 advisories
Filter by severity
h11 accepts some malformed Chunked-Encoding bodies
Critical
CVE-2025-43859
was published
for
h11
(pip)
Apr 24, 2025
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct...
High
Unreviewed
CVE-2024-33452
was published
Apr 22, 2025
croogo Host header injection
Moderate
CVE-2024-29643
was published
for
croogo/croogo
(Composer)
Apr 21, 2025
CVE-2025-1386- Query smuggling in ch-go library
Moderate
CVE-2025-1386
was published
for
github.com/ClickHouse/ch-go
(Go)
Apr 12, 2025
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This...
High
Unreviewed
CVE-2024-53868
was published
Apr 3, 2025
Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers
High
CVE-2025-31137
was published
for
@react-router/express
(npm)
Apr 1, 2025
IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack...
Moderate
Unreviewed
CVE-2022-39163
was published
Mar 26, 2025
Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via...
Moderate
Unreviewed
CVE-2025-30346
was published
Mar 21, 2025
Gunicorn HTTP Request/Response Smuggling vulnerability
High
CVE-2024-6827
was published
for
gunicorn
(pip)
Mar 20, 2025
HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers...
High
Unreviewed
CVE-2024-10264
was published
Mar 20, 2025
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
Moderate
Unreviewed
CVE-2025-29904
was published
Mar 12, 2025
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in...
Critical
Unreviewed
CVE-2025-1867
was published
Mar 3, 2025
In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the...
Moderate
Unreviewed
CVE-2024-56908
was published
Feb 14, 2025
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access...
Moderate
Unreviewed
CVE-2025-0752
was published
Jan 28, 2025
In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to...
Critical
Unreviewed
CVE-2023-29476
was published
Dec 14, 2024
io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
High
CVE-2024-12397
was published
for
io.quarkus.http:quarkus-http-core
(Maven)
Dec 12, 2024
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in...
Moderate
Unreviewed
CVE-2024-53008
was published
Nov 28, 2024
Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
Moderate
CVE-2024-9666
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 25, 2024
Duplicate Advisory: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
Moderate
GHSA-pcx7-8hxg-j823
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 25, 2024
•
withdrawn
aiohttp allows request smuggling due to incorrect parsing of chunk extensions
Moderate
CVE-2024-52304
was published
for
aiohttp
(pip)
Nov 18, 2024
Undertow incorrectly parses cookies
High
CVE-2023-4639
was published
for
io.undertow:undertow-core
(Maven)
Nov 17, 2024
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0'...
High
Unreviewed
CVE-2024-52530
was published
Nov 11, 2024
Waitress has request processing race condition in HTTP pipelining with invalid first request
Critical
CVE-2024-49768
was published
for
waitress
(pip)
Oct 29, 2024
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services...
Moderate
Unreviewed
CVE-2024-21281
was published
Oct 15, 2024
An issue in kmqtt v0.2.7 allows attackers to cause a Denial of Service(DoS) via a crafted request.
High
Unreviewed
CVE-2024-44775
was published
Oct 15, 2024
ProTip!
Advisories are also available from the
GraphQL API