GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
114 advisories
Filter by severity
Cowboy: Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
High
CVE-2026-8466
was published
for
cowboy
(Erlang)
May 13, 2026
cowlib: Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
High
CVE-2026-43970
was published
for
cowlib
(Erlang)
May 13, 2026
Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS
Moderate
CVE-2026-32686
was published
for
decimal
(Erlang)
May 12, 2026
cowlib cow_http_te module: Uncontrolled Resource Consumption vulnerability allows Excessive Allocation
High
CVE-2026-7790
was published
for
cowlib
(Erlang)
May 11, 2026
cowlib: Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
Low
CVE-2026-43969
was published
for
cowlib
(Erlang)
May 11, 2026
ninenines cowlib: Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability allows SSE event splitting and injection via unvalidated field values
Moderate
CVE-2026-43968
was published
for
cowlib
(Erlang)
May 11, 2026
Phoenix: Long-poll NDJSON body splitting causes large memory allocation
High
CVE-2026-32689
was published
for
phoenix
(Erlang)
May 8, 2026
absinthe_plug Has a Cross-site Scripting vulnerability
Low
CVE-2026-42794
was published
for
absinthe_plug
(Erlang)
May 8, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
CVE-2026-44700
was published
for
ex_webrtc
(Erlang)
May 8, 2026
Bandit HTTP/2 Frame Size Limit Bypass via Late Buffer Check Enables Memory Exhaustion
Moderate
CVE-2026-42788
was published
for
bandit
(Erlang)
May 7, 2026
Bandit trusts client-supplied URI scheme on plaintext connections
Moderate
CVE-2026-39807
was published
for
bandit
(Erlang)
May 7, 2026
Bandit is vulnerable to CL.CL request smuggling via unrejected duplicate `Content-Length` header
Moderate
CVE-2026-39805
was published
for
bandit
(Erlang)
May 7, 2026
Bandit Buffers Unbounded WebSocket Continuation Frames, Allowing Unauthenticated Memory Exhaustion
High
CVE-2026-42786
was published
for
bandit
(Erlang)
May 7, 2026
Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame
High
CVE-2026-39804
was published
for
bandit
(Erlang)
May 7, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
CVE-2026-32688
was published
for
plug_cowboy
(Erlang)
May 5, 2026
wisp has Allocation of Resources Without Limits or Throttling
High
CVE-2026-32145
was published
for
wisp
(Erlang)
Apr 3, 2026
ewe Has Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Request/Response Splitting)
Moderate
CVE-2026-34715
was published
for
ewe
(Erlang)
Apr 1, 2026
Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
High
CVE-2026-34593
was published
for
ash
(Erlang)
Apr 1, 2026
elixir-nodejs has Cross-User Data Leakage or Information Disclosure due to Worker Protocol Race Condition
High
CVE-2026-33872
was published
for
nodejs
(Erlang)
Mar 26, 2026
esaml XXE vulnerability allows local file disclosure and SSRF via crafted SAML messages
Moderate
CVE-2026-28809
was published
for
esaml
(Erlang)
Mar 23, 2026
Loop with Unreachable Exit Condition ('Infinite Loop') in ewe
High
CVE-2026-32873
was published
for
ewe
(Erlang)
Mar 16, 2026
Permissive List of Allowed Inputs in ewe
Moderate
CVE-2026-32881
was published
for
ewe
(Erlang)
Mar 16, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
CVE-2026-21619
was published
for
hex_core
(Erlang)
Mar 1, 2026
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
ProTip!
Advisories are also available from the
GraphQL API