GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,426
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,670
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
44 advisories
Filter by severity
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Moderate
CVE-2026-33174
was published
for
activestorage
(RubyGems)
Mar 23, 2026
Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service
Moderate
CVE-2026-26931
was published
for
github.com/elastic/beats/v7
(Go)
Mar 19, 2026
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports
Moderate
CVE-2026-32941
was published
for
github.com/bishopfox/sliver
(Go)
Mar 17, 2026
Mattermost fails to limit the size of responses from integration action endpoints
Moderate
CVE-2026-2456
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost fails to bound memory allocation when processing DOC files
Moderate
CVE-2026-25780
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost fails to bound memory allocation when processing PSD image files
Moderate
CVE-2026-26246
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation
High
CVE-2026-25899
was published
for
github.com/gofiber/fiber/v3
(Go)
Feb 24, 2026
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
Moderate
CVE-2026-27204
was published
for
wasmtime
(Rust)
Feb 24, 2026
ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder
High
CVE-2026-25985
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
EVE Freely Allocates Buffer on The Stack With Data From Socket
Moderate
CVE-2023-43632
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpoints
Critical
CVE-2026-25579
was published
for
github.com/navidrome/navidrome
(Go)
Feb 4, 2026
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
High
CVE-2026-22803
was published
for
@sveltejs/kit
(npm)
Jan 15, 2026
MessagePack for Java Vulnerable to Remote DoS via Malicious EXT Payload Allocation
High
CVE-2026-21452
was published
for
org.msgpack:msgpack-core
(Maven)
Jan 5, 2026
rardecode: DoS risk due to unrestricted RAR dictionary sizes
Moderate
CVE-2025-11579
was published
for
github.com/nwaples/rardecode
(Go)
Oct 10, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder
High
CVE-2025-54801
was published
for
github.com/gofiber/fiber/v2
(Go)
Aug 5, 2025
File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
High
CVE-2025-53893
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 16, 2025
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
Moderate
CVE-2025-27533
was published
for
org.apache.activemq:activemq-client
(Maven)
May 7, 2025
net-imap rubygem vulnerable to possible DoS by memory exhaustion
Moderate
CVE-2025-43857
was published
for
net-imap
(RubyGems)
Apr 28, 2025
SurrealDB memory exhaustion via string::replace using regex
High
GHSA-3633-g6mg-p6qq
was published
for
surrealdb
(Rust)
Apr 11, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Moderate
CVE-2025-32386
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2025
Possible DoS by memory exhaustion in net-imap
Moderate
CVE-2025-25186
was published
for
net-imap
(RubyGems)
Feb 10, 2025
matrix-media-repo (MMR) allows a denial of service through memory exhaustion
Moderate
CVE-2024-52791
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Moderate
CVE-2024-41132
was published
for
SixLabors.ImageSharp
(NuGet)
Jul 22, 2024
@grpc/grpc-js can allocate memory for incoming messages well above configured limits
Moderate
CVE-2024-37168
was published
for
@grpc/grpc-js
(npm)
Jun 10, 2024
ProTip!
Advisories are also available from the
GraphQL API