Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Loading
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799) High
CVE-2026-63126 was published for com.squareup.wire:wire-runtime (Maven) Sep 17, 2026
thientd Credited to thientd and gladiator9797 gladiator9797 gladiator9797
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions High
CVE-2026-41849 was published for org.springframework:spring-expression (Maven) Jun 9, 2026
Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits High
CVE-2025-52520 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Jul 10, 2025
westonsteimel Credited to westonsteimel
HTTP/2 HPACK integer overflow and buffer allocation High
CVE-2023-36478 was published for org.eclipse.jetty.http2:http2-hpack (Maven) Oct 10, 2023
bismuthsalamander Credited to bismuthsalamander, samalws-tob, kaoudis, smichaels-tob, and joakime samalws-tob samalws-tob
kaoudis kaoudis smichaels-tob smichaels-tob joakime joakime
Mapbox is vulnerable to Integer Overflow High
CVE-2022-38216 was published for com.mapbox.mapboxsdk:mapbox-android-core (Maven) Aug 17, 2022
billyjbryant Credited to billyjbryant and aruneko aruneko aruneko
ProTip! Advisories are also available from the GraphQL API