Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

67 advisories

Loading
ImageMagick: Stack Overflow in MVG decoder due to missing depth check. Moderate
CVE-2026-55594 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
Axios form serializer maxDepth bypass via {} metatoken Moderate
GHSA-hcpx-6fm6-wx23 was published for axios (npm) Jul 20, 2026
fg0x0 Credited to fg0x0
Axios: Excessive recursion in formDataToJSON can cause denial of service Moderate
GHSA-42h9-826w-cgv3 was published for axios (npm) Jul 20, 2026
alcls01111 Credited to alcls01111
protobufjs : Schema-derived names can shadow runtime-significant properties Moderate
CVE-2026-54269 was published for protobufjs (npm) Jun 15, 2026
acorn421 Credited to acorn421 and dcodeIO dcodeIO dcodeIO
Spring Cloud Function Context has Uncontrolled Recursion Moderate
CVE-2026-40989 was published for org.springframework.cloud:spring-cloud-function-context (Maven) Jun 1, 2026
Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler Moderate
GHSA-mxwc-wh95-pw4g was published for trapster (pip) Jul 8, 2026
tonghuaroot Credited to tonghuaroot
ratex-parser has unbounded parser recursion that leads to stack overflow (process abort) Moderate
CVE-2026-53531 was published for ratex-parser (Rust) Jul 7, 2026
nikkoenggaliano Credited to nikkoenggaliano
MindflareX Credited to MindflareX and adamus2 adamus2 adamus2
SurrealDB vulnerable to Denial of Service due to nested types annotations Moderate
GHSA-q8qp-67f9-wr3f was published for surrealdb (Rust) Jul 1, 2026
DarkaMaul Credited to DarkaMaul
ImageMagick Vulnerable to Stack Overflow in its MVG Decoder Moderate
CVE-2026-48734 was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 25, 2026
omkhar Credited to omkhar
MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement Moderate
CVE-2026-48513 was published for MessagePack (NuGet) Jun 25, 2026
AArnott Credited to AArnott
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement Moderate
CVE-2026-48512 was published for MessagePack (NuGet) Jun 25, 2026
AArnott Credited to AArnott
SurrealDB: Denial of Service via deep operator chains Moderate
GHSA-jv2j-mqmw-xvv5 was published for surrealdb (Rust) Jun 19, 2026
ImageMagick: Stack overflow in fx operation Moderate
CVE-2026-46557 was published for Magick.NET-Q16-AnyCPU (NuGet) May 18, 2026
007bsd Credited to 007bsd
ImageMagick: Policy Bypass in MNG coder could Moderate
CVE-2026-45664 was published for Magick.NET-Q16-AnyCPU (NuGet) May 18, 2026
pucagit Credited to pucagit
Strawberry GraphQL has a Circular Fragment Reference DOS Moderate
CVE-2026-47706 was published for strawberry-graphql (pip) Jun 4, 2026
gonas0919 Credited to gonas0919, Ckk3, bellini666, and patrick91 Ckk3 Ckk3
bellini666 bellini666 patrick91 patrick91
go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion Moderate
CVE-2026-44740 was published for github.com/go-git/go-billy/v5 (Go) May 13, 2026
faran66 Credited to faran66
go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth Moderate
CVE-2026-42328 was published for github.com/ipld/go-ipld-prime (Go) May 7, 2026
yuliyu123 Credited to yuliyu123
eml_parser has recursion DoS via nested message/rfc822 attachments Moderate
CVE-2026-44844 was published for eml_parser (pip) May 8, 2026
Sebasteuo Credited to Sebasteuo
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data Moderate
CVE-2026-42039 was published for axios (npm) May 5, 2026
fg0x0 Credited to fg0x0 and 0bi0 0bi0 0bi0
Apache Commons Configuration: StackOverflowError for YAML input with cycles Moderate
CVE-2026-45205 was published for org.apache.commons:commons-configuration2 (Maven) May 14, 2026
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion Moderate
CVE-2026-45740 was published for protobufjs (npm) May 19, 2026
fasrm Credited to fasrm and dcodeIO dcodeIO dcodeIO
ProTip! Advisories are also available from the GraphQL API