GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
38 advisories
Filter by severity
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation
High
CVE-2026-25899
was published
for
github.com/gofiber/fiber/v3
(Go)
Feb 24, 2026
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
Moderate
CVE-2026-27204
was published
for
wasmtime
(Rust)
Feb 24, 2026
ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder
High
CVE-2026-25985
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
EVE Freely Allocates Buffer on The Stack With Data From Socket
Moderate
CVE-2023-43632
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpoints
Critical
CVE-2026-25579
was published
for
github.com/navidrome/navidrome
(Go)
Feb 4, 2026
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
High
CVE-2026-22803
was published
for
@sveltejs/kit
(npm)
Jan 15, 2026
MessagePack for Java Vulnerable to Remote DoS via Malicious EXT Payload Allocation
High
CVE-2026-21452
was published
for
org.msgpack:msgpack-core
(Maven)
Jan 5, 2026
rardecode: DoS risk due to unrestricted RAR dictionary sizes
Moderate
CVE-2025-11579
was published
for
github.com/nwaples/rardecode
(Go)
Oct 10, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder
High
CVE-2025-54801
was published
for
github.com/gofiber/fiber/v2
(Go)
Aug 5, 2025
File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
High
CVE-2025-53893
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 16, 2025
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
Moderate
CVE-2025-27533
was published
for
org.apache.activemq:activemq-client
(Maven)
May 7, 2025
net-imap rubygem vulnerable to possible DoS by memory exhaustion
Moderate
CVE-2025-43857
was published
for
net-imap
(RubyGems)
Apr 28, 2025
SurrealDB memory exhaustion via string::replace using regex
High
GHSA-3633-g6mg-p6qq
was published
for
surrealdb
(Rust)
Apr 11, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Moderate
CVE-2025-32386
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2025
Possible DoS by memory exhaustion in net-imap
Moderate
CVE-2025-25186
was published
for
net-imap
(RubyGems)
Feb 10, 2025
matrix-media-repo (MMR) allows a denial of service through memory exhaustion
Moderate
CVE-2024-52791
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Moderate
CVE-2024-41132
was published
for
SixLabors.ImageSharp
(NuGet)
Jul 22, 2024
@grpc/grpc-js can allocate memory for incoming messages well above configured limits
Moderate
CVE-2024-37168
was published
for
@grpc/grpc-js
(npm)
Jun 10, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
Moderate
CVE-2024-32035
was published
for
SixLabors.ImageSharp
(NuGet)
Apr 15, 2024
amphp/http-client Denial of Service via HTTP/2 CONTINUATION Frames
High
GHSA-w8gf-g2vq-j2f4
was published
for
amphp/http-client
(Composer)
Apr 3, 2024
Undertow vulnerable to denial of service
High
CVE-2023-3223
was published
for
io.undertow:undertow-parent
(Maven)
Sep 27, 2023
Duplicate Advisory: EVE Freely Allocates Buffer on The Stack With Data From Socket
Critical
GHSA-vpjr-h6fh-mw4p
was published
for
github.com/lf-edge/eve
(Go)
Sep 21, 2023
•
withdrawn
Faktory Web Dashboard can lead to denial of service(DOS) via malicious user input
High
CVE-2023-37279
was published
for
github.com/contribsys/faktory
(Go)
Sep 20, 2023
ProTip!
Advisories are also available from the
GraphQL API