GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,866
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
121 advisories
Filter by severity
mpp vulnerable to Gas Draining with low gas limit
High
GHSA-vj8p-hp9x-gh47
was published
for
mpp
(Erlang)
Sep 25, 2026
mpp vulnerable to Gas Draining with access list
Moderate
GHSA-qpxh-ff8m-c62v
was published
for
mpp
(Erlang)
Sep 25, 2026
mpp vulnerable to Gas Draining with no limit
High
GHSA-vv77-66rf-pm86
was published
for
mpp
(Erlang)
Sep 25, 2026
Ash: Private action arguments can be set by user input via string-keyed params and atomic changesets
Moderate
CVE-2026-55736
was published
for
ash
(Erlang)
Sep 24, 2026
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
High
CVE-2026-54892
was published
for
plug
(Erlang)
Sep 23, 2026
Phoenix: Unbounded channel joins per transport enables DoS over few connections
High
CVE-2026-56811
was published
for
phoenix
(Erlang)
Sep 3, 2026
Phoenix: Presence keys colliding with `Object.prototype` members break existence checks
Moderate
CVE-2026-56812
was published
for
phoenix
(Erlang)
Sep 3, 2026
AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
Critical
CVE-2026-49757
was published
for
ash_authentication
(Erlang)
Aug 25, 2026
gRPC Erlang package has unbounded gzip decompression (decompression bomb)
High
CVE-2026-53430
was published
for
grpc
(Erlang)
Aug 25, 2026
gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
High
CVE-2026-48854
was published
for
grpc
(Erlang)
Aug 25, 2026
gRPC Erlang package's path bindings are overridable by query string and request body
High
CVE-2026-48599
was published
for
grpc
(Erlang)
Aug 25, 2026
gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
Critical
CVE-2026-48853
was published
for
grpc
(Erlang)
Aug 25, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Moderate
CVE-2026-53423
was published
for
membrane_mp4_plugin
(Erlang)
Aug 18, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Moderate
CVE-2026-49756
was published
for
req
(Erlang)
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
CVE-2026-49755
was published
for
req
(Erlang)
Jul 29, 2026
Protobuf: Unbounded recursion depth in embedded-message decoding
High
CVE-2026-54451
was published
for
protobuf
(Erlang)
Jul 15, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
CVE-2026-48598
was published
for
tesla
(Erlang)
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
CVE-2026-48597
was published
for
tesla
(Erlang)
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
CVE-2026-48595
was published
for
tesla
(Erlang)
Jul 10, 2026
Tesla has decompression bomb on response body
High
CVE-2026-48594
was published
for
tesla
(Erlang)
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
CVE-2026-48596
was published
for
tesla
(Erlang)
Jul 10, 2026
mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
High
CVE-2026-48862
was published
for
mint
(Erlang)
Jul 9, 2026
mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)
High
CVE-2026-49754
was published
for
mint
(Erlang)
Jul 9, 2026
mint: Content-Length header accepts non-RFC "+" sign prefix
Moderate
CVE-2026-49753
was published
for
mint
(Erlang)
Jul 9, 2026
mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`
Low
CVE-2026-48861
was published
for
mint
(Erlang)
Jul 9, 2026
ProTip!
Advisories are also available from the
GraphQL API