GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,603
Maven
5,000+
npm
4,250
NuGet
755
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
256 advisories
Filter by severity
In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to...
Low
Unreviewed
CVE-2025-11896
was published
Oct 17, 2025
When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content...
High
Unreviewed
CVE-2025-54858
was published
Oct 15, 2025
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an...
Moderate
Unreviewed
CVE-2025-33096
was published
Oct 12, 2025
When the module renders a Svg file that contains a <pattern> element, it might end up rendering...
Critical
Unreviewed
CVE-2025-10728
was published
Oct 3, 2025
Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply...
Moderate
Unreviewed
CVE-2025-43718
was published
Oct 1, 2025
express-xss-sanitizer has an unbounded recursion depth
Moderate
CVE-2025-59364
was published
for
express-xss-sanitizer
(npm)
Sep 26, 2025
Duplicate Advisory: express-xss-sanitizer has an unbounded recursion depth
Moderate
GHSA-qhwp-454g-2gv4
was published
for
express-xss-sanitizer
(npm)
Sep 15, 2025
•
withdrawn
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a...
Moderate
Unreviewed
CVE-2025-9714
was published
Sep 10, 2025
LlamaIndex affected by a Denial of Service (DOS) in JSONReader
High
CVE-2025-5302
was published
for
llama-index-core
(pip)
Aug 26, 2025
XGrammar affected by Denial of Service by infinite recursion grammars
High
CVE-2025-57809
was published
for
xgrammar
(pip)
Aug 25, 2025
Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1...
Moderate
Unreviewed
CVE-2025-24302
was published
Aug 12, 2025
Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1...
Moderate
Unreviewed
CVE-2025-20025
was published
Aug 12, 2025
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker...
High
Unreviewed
CVE-2025-23325
was published
Aug 6, 2025
An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service...
High
Unreviewed
CVE-2025-46206
was published
Aug 4, 2025
An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an...
High
Unreviewed
CVE-2025-50420
was published
Aug 4, 2025
Duplicate Advisory: serde-json-wasm stack overflow during recursive JSON parsing
Low
GHSA-j87p-gjr6-m4pv
was published
for
serde-json-wasm
(Rust)
Jul 27, 2025
•
withdrawn
Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
Moderate
CVE-2025-48924
was published
for
commons-lang:commons-lang
(Maven)
Jul 11, 2025
Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
Moderate
CVE-2025-53864
was published
for
com.nimbusds:nimbus-jose-jwt
(Maven)
Jul 11, 2025
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
Moderate
CVE-2025-5472
was published
for
llama-index-core
(pip)
Jul 7, 2025
Duplicate Advisory: rust-protobuf crate is vulnerable to Uncontrolled Recursion, potentially leading to DoS
Moderate
GHSA-rxf6-323f-44fc
was published
for
protobuf
(Rust)
Jul 5, 2025
•
withdrawn
MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where...
High
Unreviewed
CVE-2025-6710
was published
Jun 26, 2025
protobuf-python has a potential Denial of Service issue
High
CVE-2025-4565
was published
for
protobuf
(pip)
Jun 16, 2025
In ims service, there is a possible system crash due to incorrect error handling. This could lead...
High
Unreviewed
CVE-2025-20678
was published
Jun 2, 2025
In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a...
High
Unreviewed
CVE-2025-30193
was published
May 20, 2025
LlamaIndex Vulnerable to Denial of Service (DoS)
High
CVE-2025-1752
was published
for
llama-index
(pip)
May 10, 2025
ProTip!
Advisories are also available from the
GraphQL API