GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
108 advisories
Filter by severity
Hackney has CRLF / header injection via unvalidated `domain` and `path` options
Low
CVE-2026-47069
was published
for
hackney
(Erlang)
Jun 26, 2026
Hackney: `ssl:connect/2` post-handshake upgrade has no timeout
High
CVE-2026-47071
was published
for
hackney
(Erlang)
Jun 26, 2026
Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry
High
CVE-2026-47066
was published
for
hackney
(Erlang)
Jun 26, 2026
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
Critical
CVE-2026-49454
was published
for
relyra
(Erlang)
Jun 26, 2026
earmark: Stored XSS via unescaped HTML attribute values
Moderate
CVE-2026-48591
was published
for
earmark
(Erlang)
Jun 17, 2026
PhoenixStorybook has cross-session PubSub topic injection via URL parameter
Low
CVE-2026-47068
was published
for
phoenix_storybook
(Erlang)
Jun 9, 2026
PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)
High
CVE-2026-8469
was published
for
phoenix_storybook
(Erlang)
Jun 9, 2026
PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
Critical
CVE-2026-8467
was published
for
phoenix_storybook
(Erlang)
Jun 9, 2026
cowboy and gun affected by an HTTP Request/Response Splitting vulnerability
Moderate
CVE-2026-43966
was published
for
cowboy
(Erlang)
Jun 8, 2026
gun has an Uncontrolled Resource Consumption vulnerability
High
CVE-2026-43973
was published
for
gun
(Erlang)
Jun 8, 2026
gun has an Unexpected Status Code or Return Value vulnerability
High
CVE-2026-43974
was published
for
gun
(Erlang)
Jun 8, 2026
gun_http2 has an Origin Validation Error vulnerability
Moderate
CVE-2026-43972
was published
for
gun
(Erlang)
Jun 8, 2026
Duplicate Advisory: Hackney has an Allocation of Resources Without Limits or Throttling vulnerabilit
High
GHSA-76v6-f83q-pxvh
was published
for
hackney
(Erlang)
May 26, 2026
•
withdrawn
Plug: Unbounded buffer accumulation in multipart header parsing causes denial of service
High
CVE-2026-8468
was published
for
plug
(Erlang)
May 20, 2026
Bandit: Unauthenticated DoS via chunked request trailers in Bandit HTTP/1 decoder
High
CVE-2026-39806
was published
for
bandit
(Erlang)
May 19, 2026
Bandit: Unauthenticated one-shot DoS via `Transfer-Encoding: chunked`
High
CVE-2026-39803
was published
for
bandit
(Erlang)
May 19, 2026
Postgrex: Channel-name SQL injection in `Postgrex.Notifications.listen/3`
High
CVE-2026-32687
was published
for
postgrex
(Erlang)
May 18, 2026
Absinthe: Quadratic fragment-name uniqueness check
High
CVE-2026-43967
was published
for
absinthe
(Erlang)
May 14, 2026
Absinthe: Unbounded atom creation from parsed directive name
High
CVE-2026-42793
was published
for
absinthe
(Erlang)
May 14, 2026
Cowboy: Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
High
CVE-2026-8466
was published
for
cowboy
(Erlang)
May 13, 2026
cowlib: Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
High
CVE-2026-43970
was published
for
cowlib
(Erlang)
May 13, 2026
Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS
Moderate
CVE-2026-32686
was published
for
decimal
(Erlang)
May 12, 2026
cowlib cow_http_te module: Uncontrolled Resource Consumption vulnerability allows Excessive Allocation
High
CVE-2026-7790
was published
for
cowlib
(Erlang)
May 11, 2026
cowlib: Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
Low
CVE-2026-43969
was published
for
cowlib
(Erlang)
May 11, 2026
ninenines cowlib: Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability allows SSE event splitting and injection via unvalidated field values
Moderate
CVE-2026-43968
was published
for
cowlib
(Erlang)
May 11, 2026
ProTip!
Advisories are also available from the
GraphQL API