Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS Moderate
CVE-2026-64607 was published for org.apache.httpcomponents.client5:httpclient5 (Maven) Jul 31, 2026
Lueton Credited to Lueton
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization Moderate
CVE-2026-49844 was published for org.apache.logging.log4j:log4j-api (Maven) Jul 11, 2026
ppkarwasz Credited to ppkarwasz, ashwani945, and Lueton ashwani945 ashwani945
Lueton Lueton
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK High
CVE-2026-54428 was published for org.apache.httpcomponents.core5:httpcore5-h2 (Maven) Jul 1, 2026
Lueton Credited to Lueton
JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution Moderate
CVE-2026-53914 was published for org.jetbrains.kotlin:kotlin-gradle-plugin (Maven) Jun 26, 2026
marcelstoer Credited to marcelstoer and Lueton Lueton Lueton
ProTip! Advisories are also available from the GraphQL API