Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,086 advisories

Loading
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS High
GHSA-m3wp-48jr-vr4g was published for mistralrs-server-core (Rust) Sep 10, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation High
CVE-2026-59161 was published for github.com/xuri/excelize (Go) Sep 10, 2026
DavidCarliez Credited to DavidCarliez
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service Moderate
CVE-2026-53495 was published for github.com/containerd/containerd (Go) Sep 9, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and liangjs keenanwgn keenanwgn
liangjs liangjs
e1abrador Credited to e1abrador
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads High
CVE-2026-77037 was published for multer (npm) Sep 8, 2026
dkoazw Credited to dkoazw, EmirCobanOfficial, bjohansebas, and UlisesGascon EmirCobanOfficial EmirCobanOfficial
bjohansebas bjohansebas UlisesGascon UlisesGascon
multer vulnerable to Denial of Service via oversized array index in field names High
CVE-2026-82333 was published for multer (npm) Sep 8, 2026
O4FDev Credited to O4FDev, UlisesGascon, and arpitjain099 UlisesGascon UlisesGascon
arpitjain099 arpitjain099
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources High
CVE-2026-84375 was published for js-yaml (npm) Sep 8, 2026
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing High
GHSA-j95f-988m-3j2f was published for @tiptap/core (npm) Sep 8, 2026
joostgrunwald Credited to joostgrunwald
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion Moderate
CVE-2026-84364 was published for hono (npm) Sep 8, 2026
Rikuxx0 Credited to Rikuxx0
xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser High
CVE-2026-83619 was published for @xmldom/xmldom (npm) Sep 8, 2026
karfau Credited to karfau
ProTip! Advisories are also available from the GraphQL API