Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

852 advisories

Loading
react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU High
CVE-2026-84997 was published for react/http (Composer) Sep 17, 2026
jsifuentes Credited to jsifuentes
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service High
CVE-2026-81876 was published for ca.uhn.hapi.fhir:org.hl7.fhir.r5 (Maven) Sep 17, 2026
sondt99 Credited to sondt99
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service High
CVE-2026-68523 was published for fulgur (Rust) Sep 17, 2026
ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion High
CVE-2026-85715 was published for exifreader (npm) Sep 17, 2026
alienkeric Credited to alienkeric
afldl Credited to afldl
strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption. Moderate Unreviewed
CVE-2026-78129 was published Sep 11, 2026
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle Moderate
CVE-2026-87013 was published for open-webui (pip) Sep 10, 2026
luida-ikura Credited to luida-ikura and Classic298 Classic298 Classic298
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree Moderate
CVE-2026-88000 was published for open-webui (pip) Sep 9, 2026
Classic298 Credited to Classic298
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history Moderate
CVE-2026-88002 was published for open-webui (pip) Sep 9, 2026
YashvantHange Credited to YashvantHange and Classic298 Classic298 Classic298
smol-toml: Denial of Service via malformed TOML documents High
CVE-2026-85730 was published for smol-toml (npm) Sep 9, 2026
Ravi-lk Credited to Ravi-lk
LiquidJS has an infinite loop vulnerability in its `strip_html` filter High
CVE-2026-61556 was published for liquidjs (npm) Sep 3, 2026
NariyoshiChida Credited to NariyoshiChida
pypdf: Possible infinite loop for TreeObject.insert_child Moderate
CVE-2026-84309 was published for pypdf (pip) Sep 1, 2026
alienkeric Credited to alienkeric and stefan6419846 stefan6419846 stefan6419846
ProTip! Advisories are also available from the GraphQL API