GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
221 advisories
Filter by severity
A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the...
Moderate
Unreviewed
CVE-2026-72683
was published
Aug 13, 2026
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request...
Moderate
Unreviewed
CVE-2026-72686
was published
Aug 13, 2026
Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern...
Moderate
Unreviewed
CVE-2026-72679
was published
Aug 13, 2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized...
Moderate
Unreviewed
CVE-2026-72647
was published
Aug 13, 2026
Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a...
Moderate
Unreviewed
CVE-2026-72636
was published
Aug 13, 2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data...
Moderate
Unreviewed
CVE-2026-72638
was published
Aug 13, 2026
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an...
Moderate
Unreviewed
CVE-2026-15996
was published
Aug 5, 2026
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
GeoDjango's `django...
Moderate
Unreviewed
CVE-2026-15830
was published
Aug 4, 2026
axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing...
Moderate
Unreviewed
CVE-2026-67321
was published
Aug 1, 2026
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Moderate
GHSA-r292-9mhp-454m
was published
for
tar
(npm)
Jul 24, 2026
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
Moderate
CVE-2026-55594
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially...
Moderate
Unreviewed
CVE-2026-63144
was published
Jul 22, 2026
Axios form serializer maxDepth bypass via {} metatoken
Moderate
GHSA-hcpx-6fm6-wx23
was published
for
axios
(npm)
Jul 20, 2026
Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
Moderate
CVE-2026-59927
was published
for
mistune
(pip)
Jul 20, 2026
Axios: Excessive recursion in formDataToJSON can cause denial of service
Moderate
GHSA-42h9-826w-cgv3
was published
for
axios
(npm)
Jul 20, 2026
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pmbus/adm1266) widen...
Moderate
Unreviewed
CVE-2026-64135
was published
Jul 19, 2026
SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when...
Moderate
Unreviewed
CVE-2025-71393
was published
Jul 18, 2026
Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler
Moderate
GHSA-mxwc-wh95-pw4g
was published
for
trapster
(pip)
Jul 8, 2026
ratex-parser has unbounded parser recursion that leads to stack overflow (process abort)
Moderate
CVE-2026-53531
was published
for
ratex-parser
(Rust)
Jul 7, 2026
Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the...
Moderate
Unreviewed
CVE-2026-14803
was published
Jul 6, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
Moderate
GHSA-q8qp-67f9-wr3f
was published
for
surrealdb
(Rust)
Jul 1, 2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive...
Moderate
Unreviewed
CVE-2026-56148
was published
Jul 1, 2026
A flaw was found in p11-kit. The RPC message attribute parsing functions...
Moderate
Unreviewed
CVE-2026-13757
was published
Jun 29, 2026
In the Linux kernel, the following vulnerability has been resolved:
arm64: Reserve an extra page...
Moderate
Unreviewed
CVE-2026-53288
was published
Jun 26, 2026
Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)
Moderate
GHSA-6q7j-xr26-3h2c
was published
for
Scriban
(NuGet)
Jun 26, 2026
ProTip!
Advisories are also available from the
GraphQL API