Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

528 advisories

Loading
Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early High
CVE-2026-107286 was published for pydantic-ai (pip) Oct 8, 2026
lche511 Credited to lche511
Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor Moderate
CVE-2026-107834 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
oguzylmzx Credited to oguzylmzx
undici vulnerable to Denial of Service via orphaned RetryHandler response body Moderate
CVE-2026-18149 was published for undici (npm) Sep 29, 2026
mcollina Credited to mcollina, UlisesGascon, and samuel871211 UlisesGascon UlisesGascon
samuel871211 samuel871211
Missing release of resource after effective lifetime, Comparison using wrong factors... Unknown Unreviewed
CVE-2026-79677 was published Sep 23, 2026
hewei-gikaku Credited to hewei-gikaku
Bouncy Castle: Zeroisation of sensitive key material on garbage collection relies on finalization. High
CVE-2026-13505 was published for org.bouncycastle:bc-fips (Maven) Aug 8, 2026
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS Moderate
CVE-2026-64607 was published for org.apache.httpcomponents.client5:httpclient5 (Maven) Jul 31, 2026
Lueton Credited to Lueton
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names Moderate
CVE-2026-73508 was published for io.netty:netty-codec-dns (Maven) Jul 24, 2026
violetagg Credited to violetagg
ProTip! Advisories are also available from the GraphQL API