GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
20 advisories
Filter by severity
http4s-scala-xml has an XML External Entity (XXE) processing issue
Critical
CVE-2026-61741
was published
for
org.http4s:http4s-scala-xml_2.12
(Maven)
Sep 24, 2026
Jawn: Quadratic parsing effort in AsyncParser
High
CVE-2026-61814
was published
for
org.typelevel:jawn-parser_2.12
(Maven)
Sep 23, 2026
Jawn: Uncontrolled nesting depth in JSON parser
High
CVE-2026-59990
was published
for
org.typelevel:jawn-parser_2.12
(Maven)
Sep 23, 2026
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE
High
CVE-2026-88975
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators
Moderate
CVE-2026-69201
was published
for
org.http4s:http4s-server_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2: unbounded continuation frame accumulation
High
CVE-2026-69218
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: Ember chunk parser lenience (TE.TE request smuggling)
Moderate
CVE-2026-69216
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin
Moderate
CVE-2026-69215
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
Moderate
CVE-2026-69214
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2 has an unbounded outbound frame queue
High
CVE-2026-69213
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s: DigestAuth nonce map grows unbounded
High
CVE-2026-69208
was published
for
org.http4s:http4s-ember-server_2.12
(Maven)
Sep 15, 2026
Http4s: DigestAuth allows replay of captured requests
Moderate
CVE-2026-69206
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)
High
CVE-2026-69205
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
Critical
CVE-2026-69204
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
High
CVE-2026-69203
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Http4s Ember HTTP/2: unbounded inbound body buffering
High
CVE-2026-69202
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
http4s has HTTP/2 Denial of Service with Ember Backend
High
CVE-2026-54556
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Aug 26, 2026
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
High
CVE-2026-73495
was published
for
org.http4s:blaze-http_2.12
(Maven)
Jul 24, 2026
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
High
CVE-2026-73494
was published
for
org.http4s:blaze-http_2.13
(Maven)
Jul 24, 2026
Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
Moderate
CVE-2025-59822
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 23, 2025
ProTip!
Advisories are also available from the
GraphQL API