GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
114 advisories
Filter by severity
AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
Critical
CVE-2026-49757
was published
for
ash_authentication
(Erlang)
Aug 25, 2026
gRPC Erlang package has unbounded gzip decompression (decompression bomb)
High
CVE-2026-53430
was published
for
grpc
(Erlang)
Aug 25, 2026
gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
High
CVE-2026-48854
was published
for
grpc
(Erlang)
Aug 25, 2026
gRPC Erlang package's path bindings are overridable by query string and request body
High
CVE-2026-48599
was published
for
grpc
(Erlang)
Aug 25, 2026
gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
Critical
CVE-2026-48853
was published
for
grpc
(Erlang)
Aug 25, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Moderate
CVE-2026-53423
was published
for
membrane_mp4_plugin
(Erlang)
Aug 18, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Moderate
CVE-2026-49756
was published
for
req
(Erlang)
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
CVE-2026-49755
was published
for
req
(Erlang)
Jul 29, 2026
Protobuf: Unbounded recursion depth in embedded-message decoding
High
CVE-2026-54451
was published
for
protobuf
(Erlang)
Jul 15, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
CVE-2026-48598
was published
for
tesla
(Erlang)
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
CVE-2026-48597
was published
for
tesla
(Erlang)
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
CVE-2026-48595
was published
for
tesla
(Erlang)
Jul 10, 2026
Tesla has decompression bomb on response body
High
CVE-2026-48594
was published
for
tesla
(Erlang)
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
CVE-2026-48596
was published
for
tesla
(Erlang)
Jul 10, 2026
mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
High
CVE-2026-48862
was published
for
mint
(Erlang)
Jul 9, 2026
mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)
High
CVE-2026-49754
was published
for
mint
(Erlang)
Jul 9, 2026
mint: Content-Length header accepts non-RFC "+" sign prefix
Moderate
CVE-2026-49753
was published
for
mint
(Erlang)
Jul 9, 2026
mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`
Low
CVE-2026-48861
was published
for
mint
(Erlang)
Jul 9, 2026
QUIC has Broken TLS verification
Critical
CVE-2026-49457
was published
for
quic
(Erlang)
Jul 1, 2026
oban_web missing authorization check on `save-job` event handler
Moderate
CVE-2026-48592
was published
for
oban_web
(Erlang)
Jun 30, 2026
oban_web: Unbounded range expansion in cron describe causes memory exhaustion
Moderate
CVE-2026-48593
was published
for
oban_web
(Erlang)
Jun 30, 2026
RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
Moderate
CVE-2023-46118
was published
for
rabbit_common
(Erlang)
Jun 30, 2026
RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins
Moderate
CVE-2022-31008
was published
for
rabbit_common
(Erlang)
Jun 30, 2026
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
High
CVE-2026-47074
was published
for
ex_aws_sns
(Erlang)
Jun 26, 2026
Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes
High
CVE-2026-47067
was published
for
hackney
(Erlang)
Jun 26, 2026
ProTip!
Advisories are also available from the
GraphQL API