GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,196
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,483
Pub
12
RubyGems
992
Rust
1,186
Swift
51
Unreviewed advisories
All unreviewed
5,000+
50 advisories
Filter by severity
dr_libs version 0.13.3 and earlier contain an uncontrolled memory allocation vulnerability in...
Moderate
Unreviewed
CVE-2026-32836
was published
Mar 17, 2026
Mattermost fails to limit the size of responses from integration action endpoints
Moderate
CVE-2026-2456
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost fails to bound memory allocation when processing PSD image files
Moderate
CVE-2026-26246
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost fails to bound memory allocation when processing DOC files
Moderate
CVE-2026-25780
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports
Moderate
GHSA-97vp-pwqj-46qc
was published
for
github.com/bishopfox/sliver
(Go)
Mar 17, 2026
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
Moderate
CVE-2026-27204
was published
for
wasmtime
(Rust)
Feb 24, 2026
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable...
Moderate
Unreviewed
CVE-2025-2668
was published
Jan 31, 2026
EVE Freely Allocates Buffer on The Stack With Data From Socket
Moderate
CVE-2023-43632
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
Issue summary: A TLS 1.3 connection using certificate compression can be
forced to allocate a...
Moderate
Unreviewed
CVE-2025-66199
was published
Jan 27, 2026
rardecode: DoS risk due to unrestricted RAR dictionary sizes
Moderate
CVE-2025-11579
was published
for
github.com/nwaples/rardecode
(Go)
Oct 10, 2025
net-imap rubygem vulnerable to possible DoS by memory exhaustion
Moderate
CVE-2025-43857
was published
for
net-imap
(RubyGems)
Apr 28, 2025
IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX...
Moderate
Unreviewed
CVE-2025-2534
was published
Nov 7, 2025
dm_table_create in drivers/md/dm-table.c in the Linux kernel through 6.7.4 can attempt to (in...
Moderate
Unreviewed
CVE-2023-52429
was published
Feb 12, 2024
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an...
Moderate
Unreviewed
CVE-2024-37529
was published
Aug 14, 2024
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an...
Moderate
Unreviewed
CVE-2024-35152
was published
Aug 14, 2024
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
Moderate
CVE-2025-27533
was published
for
org.apache.activemq:activemq-client
(Maven)
May 7, 2025
matrix-media-repo (MMR) allows a denial of service through memory exhaustion
Moderate
CVE-2024-52791
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled...
Moderate
Unreviewed
CVE-2025-4605
was published
Jun 11, 2025
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server...
Moderate
Unreviewed
CVE-2025-2533
was published
Jul 29, 2025
Redis through 7.4.3 allows memory consumption via a multi-bulk command composed of many bulks,...
Moderate
Unreviewed
CVE-2025-46686
was published
Jul 23, 2025
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1...
Moderate
Unreviewed
CVE-2025-2518
was published
May 29, 2025
Possible DoS by memory exhaustion in net-imap
Moderate
CVE-2025-25186
was published
for
net-imap
(RubyGems)
Feb 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Moderate
CVE-2025-32386
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2025
An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48...
Moderate
Unreviewed
CVE-2025-29491
was published
Mar 27, 2025
ProTip!
Advisories are also available from the
GraphQL API