GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,561 advisories
Filter by severity
OpenClaw: Unauthorized Telegram Senders Trigger Media Download and Disk Write Before Access Check
Moderate
GHSA-h656-5vcf-cm23
was published
for
openclaw
(npm)
Mar 3, 2026
Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
High
CVE-2026-27601
was published
for
underscore
(npm)
Mar 3, 2026
Django vulnerable to Uncontrolled Resource Consumption
High
CVE-2026-25673
was published
for
Django
(pip)
Mar 3, 2026
OpenClaw has hook auth rate limiter bypass via IPv4-mapped IPv6 client key variants
Moderate
GHSA-5847-rm3g-23mw
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw voice-call media stream validated streams after upgrade, which could allow pre-start unauthenticated sockets to increase resource pressure
High
CVE-2026-32062
was published
for
@openclaw/voice-call
(npm)
Mar 2, 2026
OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channels
Moderate
GHSA-rxxp-482v-7mrh
was published
for
openclaw
(npm)
Mar 2, 2026
OliveTin has Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpoint
High
CVE-2026-28342
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 2, 2026
joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)
High
CVE-2026-27932
was published
for
joserfc
(pip)
Mar 2, 2026
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
Low
GHSA-fpg4-jhqr-589c
was published
for
@sveltejs/kit
(npm)
Feb 28, 2026
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
Moderate
GHSA-72hv-8253-57qq
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Feb 28, 2026
Astro has memory exhaustion DoS due to missing request body size limit in Server Actions
Moderate
CVE-2026-27729
was published
for
@astrojs/node
(npm)
Feb 25, 2026
zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service
Moderate
CVE-2026-27695
was published
for
zae-limiter
(pip)
Feb 25, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18...
Moderate
Unreviewed
CVE-2025-3525
was published
Feb 25, 2026
An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8...
Moderate
Unreviewed
CVE-2026-2845
was published
Feb 25, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18...
High
Unreviewed
CVE-2026-1662
was published
Feb 25, 2026
GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 before 18.9.1 that...
Moderate
Unreviewed
CVE-2026-1725
was published
Feb 25, 2026
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13...
Moderate
Unreviewed
CVE-2026-3201
was published
Feb 25, 2026
Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance
Moderate
CVE-2026-27572
was published
for
wasmtime
(Rust)
Feb 24, 2026
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation
High
CVE-2026-25899
was published
for
github.com/gofiber/fiber/v3
(Go)
Feb 24, 2026
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
Moderate
CVE-2026-27204
was published
for
wasmtime
(Rust)
Feb 24, 2026
nats-server websockets are vulnerable to pre-auth memory DoS
Moderate
CVE-2026-27571
was published
for
github.com/nats-io/nats-server
(Go)
Feb 24, 2026
ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder
High
CVE-2026-25985
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits
Moderate
CVE-2026-26047
was published
for
moodle/moodle
(Composer)
Feb 21, 2026
Memory exhaustion in SvelteKit remote form deserialization (experimental only)
Moderate
GHSA-vrhm-gvg7-fpcf
was published
for
@sveltejs/kit
(npm)
Feb 19, 2026
devalue affected by CPU and memory amplification from sparse arrays
Low
GHSA-33hq-fvwr-56pm
was published
for
devalue
(npm)
Feb 19, 2026
ProTip!
Advisories are also available from the
GraphQL API