GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
119 advisories
Filter by severity
When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content...
High
Unreviewed
CVE-2025-54858
was published
Oct 15, 2025
LlamaIndex affected by a Denial of Service (DOS) in JSONReader
High
CVE-2025-5302
was published
for
llama-index-core
(pip)
Aug 26, 2025
XGrammar affected by Denial of Service by infinite recursion grammars
High
CVE-2025-57809
was published
for
xgrammar
(pip)
Aug 25, 2025
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker...
High
Unreviewed
CVE-2025-23325
was published
Aug 6, 2025
An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service...
High
Unreviewed
CVE-2025-46206
was published
Aug 4, 2025
An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an...
High
Unreviewed
CVE-2025-50420
was published
Aug 4, 2025
MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where...
High
Unreviewed
CVE-2025-6710
was published
Jun 26, 2025
protobuf-python has a potential Denial of Service issue
High
CVE-2025-4565
was published
for
protobuf
(pip)
Jun 16, 2025
In ims service, there is a possible system crash due to incorrect error handling. This could lead...
High
Unreviewed
CVE-2025-20678
was published
Jun 2, 2025
In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a...
High
Unreviewed
CVE-2025-30193
was published
May 20, 2025
LlamaIndex Vulnerable to Denial of Service (DoS)
High
CVE-2025-1752
was published
for
llama-index
(pip)
May 10, 2025
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive...
High
Unreviewed
CVE-2024-8176
was published
Mar 14, 2025
Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows...
High
Unreviewed
CVE-2025-1492
was published
Feb 20, 2025
Netplex Json-smart Uncontrolled Recursion vulnerability
High
CVE-2024-57699
was published
for
net.minidev:json-smart
(Maven)
Feb 6, 2025
ASA-2024-0012, ASA-2024-0013: CosmosSDK: Transaction decoding may result in a stack overflow or resource exhaustion
High
GHSA-8wcc-m6j2-qxvm
was published
for
cosmossdk.io/x/tx
(Go)
Dec 16, 2024
In Faust 2.23.1, an input file with the lines "// r visualisation tCst" and "//process = +: L:...
High
Unreviewed
CVE-2021-41737
was published
Nov 11, 2024
Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic...
High
Unreviewed
CVE-2024-34158
was published
Sep 6, 2024
Apollo Query Planner and Apollo Gateway may infinitely loop on sufficiently complex queries
High
CVE-2024-43414
was published
for
@apollo/gateway
(npm)
Aug 27, 2024
Secure Boot Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-37973
was published
Jul 9, 2024
Undertow Denial of Service vulnerability
High
CVE-2024-5971
was published
for
io.undertow:undertow-core
(Maven)
Jul 8, 2024
In the Linux kernel, the following vulnerability has been resolved:
KVM: PPC: Book3S HV: Fix...
High
Unreviewed
CVE-2021-47465
was published
May 22, 2024
HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.
High
Unreviewed
CVE-2024-32609
was published
May 14, 2024
Duplicate Advisory: sqlparse parsing heavily nested list leads to Denial of Service
High
GHSA-62qf-jcq8-8gxw
was published
for
sqlparse
(pip)
Apr 30, 2024
•
withdrawn
sqlparse parsing heavily nested list leads to Denial of Service
High
CVE-2024-4340
was published
for
sqlparse
(pip)
Apr 15, 2024
ProTip!
Advisories are also available from the
GraphQL API