Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

81 advisories

Loading
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion High
CVE-2026-48059 was published for io.netty:netty-codec-haproxy (Maven) Jun 11, 2026
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts Moderate
CVE-2026-55767 was published for guzzlehttp/guzzle (Composer) Jun 19, 2026
iliaal Credited to iliaal and EchoTydes EchoTydes EchoTydes
chaitanyagarware Credited to chaitanyagarware
naxus-audit Credited to naxus-audit and nijel nijel nijel
Keycloak: Denial of Service via specially crafted SAML input High
CVE-2026-7307 was published for org.keycloak:keycloak-saml-core (Maven) May 19, 2026
Memory corruption while processing fastboot OEM commands. High Unreviewed
CVE-2026-24087 was published Jun 2, 2026
Memory Corruption when processing fastboot commands to set display mode. High Unreviewed
CVE-2026-24092 was published Jun 2, 2026
Memory corruption while processing fastboot commands with invalid input. High Unreviewed
CVE-2026-24089 was published Jun 2, 2026
Rack::Request accepts invalid Host characters, enabling host allowlist bypass Moderate
CVE-2026-34835 was published for rack (RubyGems) Apr 2, 2026
th4s1s Credited to th4s1s, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
Duplicate Advisory: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict High
GHSA-jj37-3377-m6vv was published for nodemailer (npm) Nov 14, 2025 withdrawn
ProTip! Advisories are also available from the GraphQL API