Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

23 advisories

Loading
Mermaid XY Charts are vulnerable to an infinite loop DoS Moderate
CVE-2026-71436 was published for mermaid (npm) Aug 6, 2026
aloisklink Credited to aloisklink
veraPDF Parser DoS via PostScript Type 1 Font Programs Moderate
CVE-2026-54081 was published for org.verapdf:parser (Maven) Jul 29, 2026
wodzen Credited to wodzen
veraPDF Parser DoS via PostScript CMap Streams Moderate
CVE-2026-54080 was published for org.verapdf:parser (Maven) Jul 29, 2026
wodzen Credited to wodzen
Guzzle: Unbounded response cookies risk denial of service Moderate
CVE-2026-67353 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Meridian: Multiple defense-in-depth gaps (collection/depth caps, telemetry, retry, fan-out) High
GHSA-f5v8-v6q3-q4h6 was published for Meridian.Mapping (NuGet) Apr 16, 2026
weixin4j has Improperly Controlled Sequential Memory Allocation Moderate
CVE-2026-24819 was published for com.foxinmy:weixin4j-base (Maven) Jan 27, 2026
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service Moderate Unreviewed
CVE-2025-13945 was published Dec 3, 2025
SmallRye Fault Tolerance out-of-memory (OOM) issue High
CVE-2025-2240 was published for io.smallrye:smallrye-fault-tolerance-core (Maven) Mar 12, 2025
claudio4j Credited to claudio4j
ProTip! Advisories are also available from the GraphQL API