Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
HTTP/2 Stream Cancellation Attack Moderate
CVE-2023-44487 was published for com.typesafe.akka:akka-http-core (Go) Oct 10, 2023
joakime Credited to joakime, faroukfaiz10, DuyTran-TomTom, derekheld, ebickle, and westonsteimel faroukfaiz10 faroukfaiz10
DuyTran-TomTom DuyTran-TomTom derekheld derekheld ebickle ebickle westonsteimel westonsteimel
HTTP/2 HPACK integer overflow and buffer allocation High
CVE-2023-36478 was published for org.eclipse.jetty.http2:http2-hpack (Maven) Oct 10, 2023
bismuthsalamander Credited to bismuthsalamander, samalws-tob, kaoudis, smichaels-tob, and joakime samalws-tob samalws-tob
kaoudis kaoudis smichaels-tob smichaels-tob joakime joakime
Jetty vulnerable to errant command quoting in CGI Servlet Low
CVE-2023-36479 was published for org.eclipse.jetty.ee10:jetty-ee10-servlets (Maven) Sep 14, 2023
bismuthsalamander Credited to bismuthsalamander, kaoudis, and joakime kaoudis kaoudis
joakime joakime
Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations Low
GHSA-58qw-p7qm-5rvh was published for org.eclipse.jetty:jetty-xml (Maven) Jul 10, 2023
uriyay-jfrog Credited to uriyay-jfrog, joakime, chadlwilson, and timtebeek joakime joakime
chadlwilson chadlwilson timtebeek timtebeek
ProTip! Advisories are also available from the GraphQL API