GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
975
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
95 advisories
Filter by severity
@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
High
CVE-2026-50171
was published
for
@angular/common
(npm)
Jun 15, 2026
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
Moderate
CVE-2026-48156
was published
for
pypdf
(pip)
Jun 12, 2026
OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU
Moderate
CVE-2026-45680
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
Phpseclib needs guardrails on large binaryfield integers
High
CVE-2023-49316
was published
for
phpseclib/phpseclib
(Composer)
May 8, 2026
pypdf: Possible long runtimes for wrong size values in incremental mode
Moderate
CVE-2026-41313
was published
for
pypdf
(pip)
Apr 16, 2026
python-multipart affected by Denial of Service via large multipart preamble or epilogue data
Moderate
CVE-2026-40347
was published
for
python-multipart
(pip)
Apr 15, 2026
pypdf has long runtimes for wrong size values in cross-reference and object streams
Moderate
CVE-2026-41168
was published
for
pypdf
(pip)
Apr 15, 2026
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
Moderate
CVE-2026-34043
was published
for
serialize-javascript
(npm)
Mar 27, 2026
pypdf has possible long runtimes/large memory usage for large /ToUnicode streams
Moderate
CVE-2026-27025
was published
for
pypdf
(pip)
Feb 18, 2026
Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in...
Moderate
Unreviewed
CVE-2025-55181
was published
Dec 3, 2025
pypdf possibly loops infinitely when reading DCT inline images without EOF marker
Moderate
CVE-2025-62707
was published
for
pypdf
(pip)
Oct 22, 2025
Finance.js vulnerable to DoS via the IRR function’s depth parameter
High
CVE-2025-56571
was published
for
financejs
(npm)
Sep 30, 2025
In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a...
High
Unreviewed
CVE-2024-4227
was published
Jan 15, 2025
In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106),...
Moderate
Unreviewed
CVE-2024-8049
was published
Nov 13, 2024
In the Linux kernel, the following vulnerability has been resolved:
bpf: Add schedule points in...
Low
Unreviewed
CVE-2022-48939
was published
Aug 22, 2024
In the Linux kernel, the following vulnerability has been resolved:
firmware: cs_dsp: Validate...
Moderate
Unreviewed
CVE-2024-42237
was published
Aug 7, 2024
In the Linux kernel, the following vulnerability has been resolved:
ionic: use...
Moderate
Unreviewed
CVE-2024-42071
was published
Jul 29, 2024
Issue summary: Checking excessively long DSA keys or parameters may be very
slow.
Impact summary...
Moderate
Unreviewed
CVE-2024-4603
was published
May 16, 2024
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of...
High
Unreviewed
CVE-2024-0842
was published
Feb 9, 2024
Liferay Portal denial-of-service vulnerability
Moderate
CVE-2024-25144
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 8, 2024
Denial of service in HashiCorp Consul
High
CVE-2020-25201
was published
for
github.com/hashicorp/consul
(Go)
Jan 31, 2024
Duplicate Advisory: phpseclib vulnerable to denial of service
High
GHSA-jpr7-q523-hx25
was published
for
phpseclib/phpseclib
(Composer)
Nov 27, 2023
•
withdrawn
Eclipse Parsson Denial of Service vulnerability
Moderate
CVE-2023-4043
was published
for
org.eclipse.parsson:project
(Maven)
Nov 3, 2023
In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server...
High
Unreviewed
CVE-2023-5632
was published
Oct 18, 2023
Golang TIFF decoder vulnerable to excessive CPU consumption
Moderate
CVE-2023-29407
was published
for
golang.org/x/image
(Go)
Aug 2, 2023
ProTip!
Advisories are also available from the
GraphQL API