GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,322 advisories
Filter by severity
Bugsink: DOS using large numbers of event tags
Moderate
CVE-2026-53954
was published
for
bugsink
(pip)
Jun 5, 2026
klever-go: REST API slow-header connection exhaustion via Gin Engine.Run
High
CVE-2026-52880
was published
for
github.com/klever-io/klever-go
(Go)
Jun 5, 2026
klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS
High
CVE-2026-52879
was published
for
github.com/klever-io/klever-go
(Go)
Jun 5, 2026
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS
Moderate
CVE-2026-49343
was published
for
github.com/klever-io/klever-go
(Go)
Jun 5, 2026
Klever-Go KVM: Hash-array amplification in P2P resolver request handling
High
CVE-2026-47249
was published
for
github.com/klever-io/klever-go
(Go)
Jun 5, 2026
Vantage6: No limit on emails sent for password/MFA reset
Low
CVE-2024-24769
was published
for
vantage6
(pip)
Jun 5, 2026
Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS)
High
GHSA-74m6-4hjp-7226
was published
for
github.com/klever-io/klever-go
(Go)
Jun 4, 2026
Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
Moderate
CVE-2026-47707
was published
for
strawberry-graphql
(pip)
Jun 4, 2026
Strawberry GraphQL has a Circular Fragment Reference DOS
Moderate
CVE-2026-47706
was published
for
strawberry-graphql
(pip)
Jun 4, 2026
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
High
CVE-2026-44496
was published
for
axios
(npm)
Jun 4, 2026
Keystone: GraphQL API Endpoint Lacks Query Depth Limits
Low
CVE-2026-10802
was published
for
@keystone-6/core
(npm)
Jun 4, 2026
Docling Core: Insufficient validation of image reference URIs
High
CVE-2026-44019
was published
for
docling-core
(pip)
Jun 3, 2026
Docling: Unsafe URI and Path Handling in HTML Backend
High
CVE-2026-47214
was published
for
docling
(pip)
Jun 3, 2026
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
High
CVE-2026-42342
was published
for
@remix-run/server-runtime
(npm)
Jun 3, 2026
Code Index MCP is vulnerable to Uncontrolled Resource Consumption
Low
CVE-2026-10692
was published
for
code-index-mcp
(pip)
Jun 3, 2026
DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption
Low
CVE-2026-10691
was published
for
@wonderwhy-er/desktop-commander
(npm)
Jun 3, 2026
Claw Orchestrator has inefficient regular expression complexity via validateRegex()
Moderate
CVE-2026-10291
was published
for
@enderfga/claw-orchestrator
(npm)
Jun 2, 2026
Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer
High
CVE-2026-49361
was published
for
org.apache.fluss:fluss-common
(Maven)
Jun 1, 2026
hermes-agent has an Uncontrolled Resource Consumption issue
Moderate
CVE-2026-10224
was published
for
hermes-agent
(pip)
Jun 1, 2026
zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood
Moderate
CVE-2026-47184
was published
for
zeroconf
(pip)
May 29, 2026
zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
Moderate
CVE-2026-47183
was published
for
zeroconf
(pip)
May 29, 2026
go-git: Malformed Git object data may cause panics or resource exhaustion
Moderate
GHSA-w5pp-99ch-qj29
was published
for
github.com/go-git/go-git/v5
(Go)
May 29, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
CVE-2026-45756
was published
for
symfony/json-path
(Composer)
May 28, 2026
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
High
CVE-2026-45357
was published
for
liquidjs
(npm)
May 27, 2026
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
Moderate
CVE-2026-44645
was published
for
liquidjs
(npm)
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API