Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,171 advisories

Loading
romain-deperne Credited to romain-deperne
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns Moderate
CVE-2026-86000 was published for soupsieve (pip) Sep 17, 2026
kaimandalic Credited to kaimandalic
kaimandalic Credited to kaimandalic
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service High
CVE-2026-81876 was published for ca.uhn.hapi.fhir:org.hl7.fhir.r5 (Maven) Sep 17, 2026
sondt99 Credited to sondt99
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service High
CVE-2026-81875 was published for ca.uhn.hapi.fhir:org.hl7.fhir.r5 (Maven) Sep 17, 2026
sondt99 Credited to sondt99
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service High
CVE-2026-68523 was published for fulgur (Rust) Sep 17, 2026
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service High
CVE-2026-85721 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation Moderate
CVE-2026-69147 was published for vllm (pip) Sep 17, 2026
rexpository Credited to rexpository and jperezdealgaba jperezdealgaba jperezdealgaba
hewei-gikaku Credited to hewei-gikaku
node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion High
CVE-2026-68904 was published for node-opcua (npm) Sep 16, 2026
Velluso Credited to Velluso and erossignon erossignon erossignon
ProTip! Advisories are also available from the GraphQL API