GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
26 advisories
Filter by severity
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
High
CVE-2026-59933
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
High
CVE-2026-59932
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
SimpleSAMLphp has Possible DoS via XPath Transform
High
CVE-2026-49289
was published
for
simplesamlphp/saml2
(Composer)
Jul 2, 2026
PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service
High
GHSA-3prj-6hqw-cm82
was published
for
web-token/jwt-framework
(Composer)
Jun 18, 2026
Phpseclib needs guardrails on large binaryfield integers
High
CVE-2023-49316
was published
for
phpseclib/phpseclib
(Composer)
May 8, 2026
phpseclib guardrails needed on OID length
High
CVE-2024-27355
was published
for
phpseclib/phpseclib
(Composer)
May 8, 2026
phpseclib: guardrails needed on isPrime and randomPrime
High
CVE-2024-27354
was published
for
phpseclib/phpseclib
(Composer)
May 6, 2026
phpseclib has a CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()
High
CVE-2026-44167
was published
for
phpseclib/phpseclib
(Composer)
May 5, 2026
PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
High
CVE-2026-40902
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 29, 2026
PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
High
CVE-2026-40863
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 29, 2026
PocketMine-MP: LogDoS by large complex unknown property logging in clientData in LoginPacket
High
GHSA-h6rj-3m53-887h
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 6, 2026
Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion
High
CVE-2026-6409
was published
for
google/protobuf
(Composer)
Mar 25, 2026
SimpleJWT has an Unauthenticated Denial of Service via JWE header tampering
High
CVE-2026-33204
was published
for
kelvinmo/simplejwt
(Composer)
Mar 18, 2026
Duplicate Advisory: phpseclib does not properly limit the ASN1 OID length
High
GHSA-jr22-8qgm-4q87
was published
for
phpseclib/phpseclib
(Composer)
Mar 2, 2024
•
withdrawn
Duplicate Advisory: phpseclib: guardrails needed on isPrime and randomPrime
High
GHSA-hg35-mp25-qf6h
was published
for
phpseclib/phpseclib
(Composer)
Mar 2, 2024
•
withdrawn
Uncontrolled Resource Consumption in moodle
High
CVE-2024-25978
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
Duplicate Advisory: phpseclib vulnerable to denial of service
High
GHSA-jpr7-q523-hx25
was published
for
phpseclib/phpseclib
(Composer)
Nov 27, 2023
•
withdrawn
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries
High
CVE-2023-40180
was published
for
silverstripe/graphql
(Composer)
Oct 17, 2023
hjson stack exhaustion vulnerability
High
CVE-2023-34620
was published
for
github.com/hjson/hjson-go/v4
(Composer)
Jun 14, 2023
Moodle vulnerable to Uncontrolled Resource Consumption
High
CVE-2021-36395
was published
for
moodle/moodle
(Composer)
Mar 6, 2023
Moodle Denial of Service
High
CVE-2020-25630
was published
for
moodle/moodle
(Composer)
May 24, 2022
Wikimedia Potential DOS due to slow WatchedItemStore::countVisitingWatchersMultiple
High
CVE-2019-12473
was published
for
mediawiki/core
(Composer)
May 24, 2022
PHP OpenID Library Denial of Service vulnerability
High
CVE-2013-4701
was published
for
openid/php-openid
(Composer)
May 17, 2022
phpMyAdmin Denial Of Service (DOS) attack
High
CVE-2016-5706
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
Moodle denial-of-service risk in the draft files area
High
CVE-2021-32476
was published
for
moodle/moodle
(Composer)
Mar 12, 2022
ProTip!
Advisories are also available from the
GraphQL API