GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
61 advisories
Filter by severity
Absinthe: Quadratic fragment-name uniqueness check
High
CVE-2026-43967
was published
for
absinthe
(Erlang)
May 14, 2026
Absinthe: Unbounded atom creation from parsed directive name
High
CVE-2026-42793
was published
for
absinthe
(Erlang)
May 14, 2026
Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS
Moderate
CVE-2026-32686
was published
for
decimal
(Erlang)
May 12, 2026
Phoenix: Long-poll NDJSON body splitting causes large memory allocation
High
CVE-2026-32689
was published
for
phoenix
(Erlang)
May 8, 2026
absinthe_plug Has a Cross-site Scripting vulnerability
Low
CVE-2026-42794
was published
for
absinthe_plug
(Erlang)
May 8, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
CVE-2026-44700
was published
for
ex_webrtc
(Erlang)
May 8, 2026
Bandit HTTP/2 Frame Size Limit Bypass via Late Buffer Check Enables Memory Exhaustion
Moderate
CVE-2026-42788
was published
for
bandit
(Erlang)
May 7, 2026
Bandit trusts client-supplied URI scheme on plaintext connections
Moderate
CVE-2026-39807
was published
for
bandit
(Erlang)
May 7, 2026
Bandit is vulnerable to CL.CL request smuggling via unrejected duplicate `Content-Length` header
Moderate
CVE-2026-39805
was published
for
bandit
(Erlang)
May 7, 2026
Bandit Buffers Unbounded WebSocket Continuation Frames, Allowing Unauthenticated Memory Exhaustion
High
CVE-2026-42786
was published
for
bandit
(Erlang)
May 7, 2026
Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame
High
CVE-2026-39804
was published
for
bandit
(Erlang)
May 7, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
CVE-2026-32688
was published
for
plug_cowboy
(Erlang)
May 5, 2026
wisp has Allocation of Resources Without Limits or Throttling
High
CVE-2026-32145
was published
for
wisp
(Erlang)
Apr 3, 2026
ewe Has Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Request/Response Splitting)
Moderate
CVE-2026-34715
was published
for
ewe
(Erlang)
Apr 1, 2026
Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
High
CVE-2026-34593
was published
for
ash
(Erlang)
Apr 1, 2026
elixir-nodejs has Cross-User Data Leakage or Information Disclosure due to Worker Protocol Race Condition
High
CVE-2026-33872
was published
for
nodejs
(Erlang)
Mar 26, 2026
esaml XXE vulnerability allows local file disclosure and SSRF via crafted SAML messages
Moderate
CVE-2026-28809
was published
for
esaml
(Erlang)
Mar 23, 2026
Loop with Unreachable Exit Condition ('Infinite Loop') in ewe
High
CVE-2026-32873
was published
for
ewe
(Erlang)
Mar 16, 2026
Permissive List of Allowed Inputs in ewe
Moderate
CVE-2026-32881
was published
for
ewe
(Erlang)
Mar 16, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
CVE-2026-21619
was published
for
hex_core
(Erlang)
Mar 1, 2026
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
Ash has authorization bypass when bypass policy condition evaluates to true
High
CVE-2025-48044
was published
for
ash
(Erlang)
Oct 17, 2025
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies
High
CVE-2025-48043
was published
for
ash
(Erlang)
Oct 13, 2025
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
High
CVE-2025-48042
was published
for
ash
(Erlang)
Sep 15, 2025
ProTip!
Advisories are also available from the
GraphQL API