Explore

Rule Explorer

Search the public rule index by CVE, GHSA, CWE, language, framework, author, or rule slug. Filter by language, framework, severity, confidence, license, and validation status.

Public rules
4797
Downloads
7.4M
Verified
4797
Authors
2
Search the rule indexUse CVE, GHSA, CWE, language, framework, package, or rule slug.
11 rules matched. Showing 11 loaded rules.
Publish rule
CVE-2026-59938: Unbounded Bytes Padding Doscve-2026-59938-unbounded-bytes-padding-dos

Data volume expansion using derived multiplier without prior maximum limits. An attacker can provide large arbitrary dimension variables that result in massive memory allocations, causing Out-Of-Memory (OOM) application denial of service. Ensure the dimensions or the resultant buffer sizes are constrained against a maximum limit before memory expansion / str

by Provallyupdated 2026-09-02Apache-2.0
2820 direct282 via packs
downloads
74quality
CVE-2026-55379: Pillow Missing Decompression Bomb Checkcve-2026-55379-pillow-missing-decompression-bomb-check

Bypassing Pillow's decompression bomb check when parsing dimensions can allow attackers to cause Denial of Service (DoS) via excessive memory allocation. Always call `Image._decompression_bomb_check((width, height))` before allocating image bitmaps internally or accumulating font metrics.

by Provallyupdated 2026-09-02Apache-2.0
2820 direct282 via packs
downloads
74quality
CVE-2026-54345: Integer Underflow Allocationcve-2026-54345-integer-underflow-allocation

An integer subtraction is used for a slice allocation size without a prior bounds check. If the right-hand side of the subtraction is larger than the left-hand side, an unsigned integer underflow may occur, resulting in an exceptionally large allocation and potentially causing a Denial of Service (DoS) via an out-of-memory crash. Verify that the left-hand si

by Provallyupdated 2026-09-02Apache-2.0
2770 direct277 via packs
downloads
74quality
CVE-2026-48155: Python Unbounded Whitespace Multiplicationcve-2026-48155-python-unbounded-whitespace-multiplication

String or list multiplication with dynamically calculated values may lead to uncontrolled memory consumption and Denial of Service (DoS). Ensure the sequence multiplier is explicitly bounded before execution.

by Provallyupdated 2026-06-23Apache-2.0
2K0 direct2K via packs
downloads
74quality
CVE-2026-42189: Unchecked Network Decoded Count Vec Capacitycve-2026-42189-unchecked-network-decoded-count-vec-capacity

An integer count decoded from untrusted external data is passed to Vec::with_capacity without bounding it against the remaining readable packet/buffer bytes. A crafted large count (e.g. u32::MAX ~4 billion) can trigger a multi-gigabyte heap allocation, crashing the process via OOM before any credential is verified (pre-auth DoS). Clamp the decoded count to t

by Provallyupdated 2026-06-12Apache-2.0
2.5K0 direct2.5K via packs
downloads
77quality
CVE-2026-33524: Unchecked Stream Array Allocationcve-2026-33524-unchecked-stream-array-allocation

An array is allocated using a length directly read from a stream or payload without bounded validation. An attacker can supply an artificially large variable length, triggering an excessive memory allocation that exhausts JVM memory (OutOfMemoryError) and leads to Denial of Service (DoS). Always check that the requested size does not exceed the remaining ava

by Provallyupdated 2026-06-12Apache-2.0
2.5K0 direct2.5K via packs
downloads
77quality
CVE-2026-22803: Eager Buffer Allocation Doscve-2026-22803-eager-buffer-allocation-dos

Eagerly allocating a buffer based on an unverified length before asynchronously reading chunks can lead to Denial of Service (DoS) via memory exhaustion. Defend against this by deferring allocation until all chunks are successfully read or validating the requested length against known HTTP Content-Length bounds.

by Provallyupdated 2026-06-12Apache-2.0
2.5K0 direct2.5K via packs
downloads
65quality
CVE-2026-21452: Unbounded Array Allocation From Method Parametercve-2026-21452-unbounded-array-allocation-from-method-parameter

An array is allocated using a size directly from a method parameter without an explicit upper bound check wrapping the allocation. If the size is controlled by an attacker during parsing or deserialization, this can lead to unbounded memory allocation, OutOfMemoryError, and Denial of Service (DoS). Validate the size against a reasonable threshold before allo

by Provallyupdated 2026-06-12Apache-2.0
2.5K0 direct2.5K via packs
downloads
81quality
All matching rules loaded.