GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,460
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,142
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
62 advisories
Filter by severity
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
Low
GHSA-qh5g-q395-cx4j
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Vantage6: No limit on emails sent for password/MFA reset
Low
CVE-2024-24769
was published
for
vantage6
(pip)
Jun 5, 2026
Keystone: GraphQL API Endpoint Lacks Query Depth Limits
Low
CVE-2026-10802
was published
for
@keystone-6/core
(npm)
Jun 4, 2026
Code Index MCP is vulnerable to Uncontrolled Resource Consumption
Low
CVE-2026-10692
was published
for
code-index-mcp
(pip)
Jun 3, 2026
DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption
Low
CVE-2026-10691
was published
for
@wonderwhy-er/desktop-commander
(npm)
Jun 3, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
CVE-2026-45756
was published
for
symfony/json-path
(Composer)
May 28, 2026
@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
Low
CVE-2026-8769
was published
for
@ai-sdk/provider-utils
(npm)
May 18, 2026
justhtml introduces denial-of-service hardening
Low
GHSA-r8cj-3554-33mr
was published
for
justhtml
(pip)
May 8, 2026
Micronaut has Unbounded `bundleCache` in `ResourceBundleMessageSource` that Allows Memory Exhaustion via `Accept-Language` Header
Low
CVE-2026-44242
was published
for
io.micronaut:micronaut-inject
(Maven)
May 6, 2026
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
Low
CVE-2026-39396
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths
Low
CVE-2026-41913
was published
for
openclaw
(npm)
Apr 9, 2026
LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
Low
CVE-2026-34166
was published
for
liquidjs
(npm)
Apr 8, 2026
Apache Cassandra has an authenticated DoS over CQL
Low
CVE-2026-32588
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Apr 7, 2026
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
Low
CVE-2026-4539
was published
for
Pygments
(pip)
Mar 22, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
CVE-2026-21619
was published
for
hex_core
(Erlang)
Mar 1, 2026
Snowflake JDBC Driver is Vulnerable to Uncontrolled Resource Consumption through SdkProxyRoutePlanner
Low
CVE-2026-3293
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Feb 27, 2026
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
Low
CVE-2026-24001
was published
for
diff
(npm)
Jan 14, 2026
pypdf has possible long runtimes for malformed startxref
Low
CVE-2026-22691
was published
for
pypdf
(pip)
Jan 9, 2026
pypdf has possible long runtimes for missing /Root object with large /Size values
Low
CVE-2026-22690
was published
for
pypdf
(pip)
Jan 9, 2026
Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
Low
CVE-2025-66453
was published
for
org.mozilla:rhino
(Maven)
Dec 3, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
CVE-2025-61921
was published
for
sinatra
(RubyGems)
Oct 10, 2025
REXML has DoS condition when parsing malformed XML file
Low
CVE-2025-58767
was published
for
rexml
(RubyGems)
Sep 17, 2025
Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability
Low
CVE-2025-9092
was published
for
org.bouncycastle:bc-fips
(Maven)
Aug 16, 2025
pm2 Regular Expression Denial of Service vulnerability
Low
CVE-2025-5891
was published
for
pm2
(npm)
Jun 9, 2025
ProTip!
Advisories are also available from the
GraphQL API