GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
866 advisories
Filter by severity
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
High
CVE-2026-19484
was published
for
@fastify/busboy
(npm)
Oct 2, 2026
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
High
CVE-2026-96780
was published
for
figlet
(npm)
Oct 2, 2026
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution
Moderate
GHSA-35mr-4567-66vg
was published
for
dulwich
(pip)
Oct 2, 2026
Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib...
High
Unreviewed
CVE-2026-85476
was published
Oct 2, 2026
Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python...
High
Unreviewed
CVE-2026-94654
was published
Oct 2, 2026
Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of...
High
Unreviewed
CVE-2026-86535
was published
Oct 2, 2026
Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy...
High
Unreviewed
CVE-2026-63570
was published
Oct 2, 2026
Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in...
High
Unreviewed
CVE-2026-63575
was published
Oct 2, 2026
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
Moderate
Unreviewed
CVE-2026-103492
was published
Oct 1, 2026
urllib3: Chunked Deflate streaming can enter an infinite loop
Moderate
CVE-2026-97688
was published
for
urllib3
(pip)
Sep 30, 2026
iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows...
High
Unreviewed
CVE-2026-102253
was published
Sep 29, 2026
TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Moderate
Unreviewed
CVE-2026-96418
was published
Sep 29, 2026
TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service
Moderate
Unreviewed
CVE-2026-95386
was published
Sep 29, 2026
Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
High
CVE-2026-101895
was published
for
@angular/platform-server
(npm)
Sep 28, 2026
HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows...
High
Unreviewed
CVE-2026-97362
was published
Sep 24, 2026
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via...
High
Unreviewed
CVE-2026-87082
was published
Sep 22, 2026
Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD...
High
Unreviewed
CVE-2026-82560
was published
Sep 19, 2026
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function...
High
Unreviewed
CVE-2026-93690
was published
Sep 18, 2026
react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU
High
CVE-2026-84997
was published
for
react/http
(Composer)
Sep 17, 2026
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
High
CVE-2026-81876
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.r5
(Maven)
Sep 17, 2026
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
High
CVE-2026-68523
was published
for
fulgur
(Rust)
Sep 17, 2026
ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion
High
CVE-2026-85715
was published
for
exifreader
(npm)
Sep 17, 2026
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
Moderate
CVE-2026-62949
was published
for
asyncssh
(pip)
Sep 17, 2026
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure...
High
Unreviewed
CVE-2026-20154
was published
Sep 16, 2026
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect...
High
Unreviewed
CVE-2026-91952
was published
Sep 15, 2026
ProTip!
Advisories are also available from the
GraphQL API