GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,406
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
92 advisories
Filter by severity
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6,...
Moderate
Unreviewed
CVE-2026-35549
was published
Apr 3, 2026
An attacker might be able to trick DNSdist into allocating too much memory while processing DNS...
Moderate
Unreviewed
CVE-2026-24030
was published
Mar 31, 2026
NVIDIA Triton Inference Server contains a vulnerability in the HTTP endpoint where an attacker...
High
Unreviewed
CVE-2026-24158
was published
Mar 24, 2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Moderate
CVE-2026-33174
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service
Moderate
CVE-2026-26931
was published
for
github.com/elastic/beats/v7
(Go)
Mar 19, 2026
dr_libs version 0.13.3 and earlier contain an uncontrolled memory allocation vulnerability in...
Moderate
Unreviewed
CVE-2026-32836
was published
Mar 17, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports
Moderate
CVE-2026-32941
was published
for
github.com/bishopfox/sliver
(Go)
Mar 17, 2026
Mattermost fails to limit the size of responses from integration action endpoints
Moderate
CVE-2026-2456
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost fails to bound memory allocation when processing DOC files
Moderate
CVE-2026-25780
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost fails to bound memory allocation when processing PSD image files
Moderate
CVE-2026-26246
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and...
High
Unreviewed
CVE-2026-28253
was published
Mar 12, 2026
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000...
High
Unreviewed
CVE-2026-20048
was published
Feb 25, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation
High
CVE-2026-25899
was published
for
github.com/gofiber/fiber/v3
(Go)
Feb 24, 2026
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
Moderate
CVE-2026-27204
was published
for
wasmtime
(Rust)
Feb 24, 2026
ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder
High
CVE-2026-25985
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
EVE Freely Allocates Buffer on The Stack With Data From Socket
Moderate
CVE-2023-43632
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpoints
Critical
CVE-2026-25579
was published
for
github.com/navidrome/navidrome
(Go)
Feb 4, 2026
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable...
Moderate
Unreviewed
CVE-2025-2668
was published
Jan 31, 2026
Issue summary: A TLS 1.3 connection using certificate compression can be
forced to allocate a...
Moderate
Unreviewed
CVE-2025-66199
was published
Jan 27, 2026
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
High
CVE-2026-22803
was published
for
@sveltejs/kit
(npm)
Jan 15, 2026
MessagePack for Java Vulnerable to Remote DoS via Malicious EXT Payload Allocation
High
CVE-2026-21452
was published
for
org.msgpack:msgpack-core
(Maven)
Jan 5, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18...
Low
Unreviewed
CVE-2025-12983
was published
Nov 15, 2025
IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX...
Moderate
Unreviewed
CVE-2025-2534
was published
Nov 7, 2025
rardecode: DoS risk due to unrestricted RAR dictionary sizes
Moderate
CVE-2025-11579
was published
for
github.com/nwaples/rardecode
(Go)
Oct 10, 2025
ProTip!
Advisories are also available from the
GraphQL API