GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
3,748 advisories
Filter by severity
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-63260
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-63261
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via...
Moderate
Unreviewed
CVE-2026-63263
was published
Jul 22, 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via...
Moderate
Unreviewed
CVE-2026-63136
was published
Jul 21, 2026
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-63139
was published
Jul 21, 2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via...
Moderate
Unreviewed
CVE-2026-56145
was published
Jul 21, 2026
Gitea SSH Key Parser Denial of Service
Moderate
CVE-2026-56657
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
pyasn1: Uncontrolled resource consumption when converting decoded REAL values
High
CVE-2026-59886
was published
for
pyasn1
(pip)
Jul 21, 2026
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
High
CVE-2026-59885
was published
for
pyasn1
(pip)
Jul 21, 2026
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
High
CVE-2026-59884
was published
for
pyssn1
(pip)
Jul 21, 2026
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
High
CVE-2026-59879
was published
for
immutable
(npm)
Jul 21, 2026
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size...
Moderate
Unreviewed
CVE-2026-59843
was published
Jul 21, 2026
The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name...
High
Unreviewed
CVE-2024-51316
was published
Jul 21, 2026
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
High
CVE-2026-59200
was published
for
Pillow
(pip)
Jul 20, 2026
Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
Moderate
GHSA-mwf2-3pr3-8698
was published
for
axios
(npm)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
Moderate
CVE-2026-59868
was published
for
js-yaml
(npm)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption
High
CVE-2026-59869
was published
for
js-yaml
(npm)
Jul 20, 2026
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
High
CVE-2026-13149
was published
for
brace-expansion
(npm)
Jul 20, 2026
Tornado: Quadratic DoS via Crafted Multipart Parameters
High
CVE-2025-67726
was published
for
tornado
(pip)
Jul 20, 2026
Tornado: Quadratic DoS via Repeated Header Coalescing
High
CVE-2025-67725
was published
for
tornado
(pip)
Jul 20, 2026
Axios: Excessive recursion in formDataToJSON can cause denial of service
Moderate
GHSA-42h9-826w-cgv3
was published
for
axios
(npm)
Jul 20, 2026
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
Moderate
GHSA-pmv8-rq9r-6j72
was published
for
axios
(npm)
Jul 20, 2026
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.
This issue affects...
High
Unreviewed
CVE-2026-59173
was published
Jul 18, 2026
IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted...
High
Unreviewed
CVE-2026-9171
was published
Jul 17, 2026
ProTip!
Advisories are also available from the
GraphQL API