Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

26 advisories

Loading
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion High
CVE-2026-59933 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion High
CVE-2026-59932 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
SimpleSAMLphp has Possible DoS via XPath Transform High
CVE-2026-49289 was published for simplesamlphp/saml2 (Composer) Jul 2, 2026
ahacker1-securesaml Credited to ahacker1-securesaml
PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service High
GHSA-3prj-6hqw-cm82 was published for web-token/jwt-framework (Composer) Jun 18, 2026
hostep Credited to hostep
Phpseclib needs guardrails on large binaryfield integers High
CVE-2023-49316 was published for phpseclib/phpseclib (Composer) May 8, 2026
phpseclib guardrails needed on OID length High
CVE-2024-27355 was published for phpseclib/phpseclib (Composer) May 8, 2026
phpseclib: guardrails needed on isPrime and randomPrime High
CVE-2024-27354 was published for phpseclib/phpseclib (Composer) May 6, 2026
phpseclib has a CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID() High
CVE-2026-44167 was published for phpseclib/phpseclib (Composer) May 5, 2026
PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions High
CVE-2026-40902 was published for phpoffice/phpspreadsheet (Composer) Apr 29, 2026
offset Credited to offset
PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader High
CVE-2026-40863 was published for phpoffice/phpspreadsheet (Composer) Apr 29, 2026
offset Credited to offset
PocketMine-MP: LogDoS by large complex unknown property logging in clientData in LoginPacket High
GHSA-h6rj-3m53-887h was published for pocketmine/pocketmine-mp (Composer) Apr 6, 2026
ArkadiaEU Credited to ArkadiaEU and dktapps dktapps dktapps
Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion High
CVE-2026-6409 was published for google/protobuf (Composer) Mar 25, 2026
34selen Credited to 34selen
SimpleJWT has an Unauthenticated Denial of Service via JWE header tampering High
CVE-2026-33204 was published for kelvinmo/simplejwt (Composer) Mar 18, 2026
edoardottt Credited to edoardottt
Duplicate Advisory: phpseclib does not properly limit the ASN1 OID length High
GHSA-jr22-8qgm-4q87 was published for phpseclib/phpseclib (Composer) Mar 2, 2024 withdrawn
Duplicate Advisory: phpseclib: guardrails needed on isPrime and randomPrime High
GHSA-hg35-mp25-qf6h was published for phpseclib/phpseclib (Composer) Mar 2, 2024 withdrawn
Uncontrolled Resource Consumption in moodle High
CVE-2024-25978 was published for moodle/moodle (Composer) Feb 19, 2024
Duplicate Advisory: phpseclib vulnerable to denial of service High
GHSA-jpr7-q523-hx25 was published for phpseclib/phpseclib (Composer) Nov 27, 2023 withdrawn
kdambekalns Credited to kdambekalns and iekadou iekadou iekadou
Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries High
CVE-2023-40180 was published for silverstripe/graphql (Composer) Oct 17, 2023
hjson stack exhaustion vulnerability High
CVE-2023-34620 was published for github.com/hjson/hjson-go/v4 (Composer) Jun 14, 2023
achibear Credited to achibear
Moodle vulnerable to Uncontrolled Resource Consumption High
CVE-2021-36395 was published for moodle/moodle (Composer) Mar 6, 2023
Moodle Denial of Service High
CVE-2020-25630 was published for moodle/moodle (Composer) May 24, 2022
Wikimedia Potential DOS due to slow WatchedItemStore::countVisitingWatchersMultiple High
CVE-2019-12473 was published for mediawiki/core (Composer) May 24, 2022
PHP OpenID Library Denial of Service vulnerability High
CVE-2013-4701 was published for openid/php-openid (Composer) May 17, 2022
phpMyAdmin Denial Of Service (DOS) attack High
CVE-2016-5706 was published for phpmyadmin/phpmyadmin (Composer) May 14, 2022
decsecre583 Credited to decsecre583
Moodle denial-of-service risk in the draft files area High
CVE-2021-32476 was published for moodle/moodle (Composer) Mar 12, 2022
ProTip! Advisories are also available from the GraphQL API