GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,695
Maven
5,000+
npm
4,321
NuGet
761
pip
4,098
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,057 advisories
Filter by severity
Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
Low
CVE-2025-66453
was published
for
org.mozilla:rhino
(Maven)
Dec 3, 2025
When reading an HTTP response from a server, if no read amount is specified, the default behavior...
Moderate
Unreviewed
CVE-2025-13836
was published
Dec 1, 2025
Grav is vulnerable to a DOS on the admin panel
Moderate
CVE-2025-66303
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
HackerOne community member Dao Hoang Anh (yoyomiski) has reported an uncontrolled resource...
Moderate
Unreviewed
CVE-2025-55128
was published
Nov 20, 2025
pypdf's LZWDecode streams be manipulated to exhaust RAM
Moderate
CVE-2025-66019
was published
for
pypdf
(pip)
Nov 24, 2025
thread-amount Vulnerable to Resource Exhaustion (Memory and Handle Leaks) on Windows and macOS
High
CVE-2025-65947
was published
for
thread-amount
(Rust)
Nov 21, 2025
BACnet Test Server versions up to and including 1.01 contains a remote denial of service...
High
Unreviewed
CVE-2020-36872
was published
Nov 27, 2025
Regular Expression Denial of Service (ReDoS) in braces
Low
CVE-2018-1109
was published
for
braces
(npm)
Jan 6, 2022
An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an...
High
Unreviewed
CVE-2025-51741
was published
Nov 25, 2025
NSSF panic due to nil pointer dereference when expiry field is omitted in NSSAIAvailability POST
High
CVE-2025-60638
was published
for
github.com/free5gc/nssf
(Go)
Nov 24, 2025
body-parser is vulnerable to denial of service when url encoding is used
Moderate
CVE-2025-13466
was published
for
body-parser
(npm)
Nov 25, 2025
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file...
High
Unreviewed
CVE-2023-52355
was published
Jan 25, 2024
The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for...
Moderate
Unreviewed
CVE-2025-59403
was published
Oct 2, 2025
net-imap rubygem vulnerable to possible DoS by memory exhaustion
Moderate
CVE-2025-43857
was published
for
net-imap
(RubyGems)
Apr 28, 2025
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service ...
High
Unreviewed
CVE-2019-9674
was published
May 24, 2022
Ribose RNP before 0.16.3 may hang when the input is malformed.
Moderate
Unreviewed
CVE-2023-29479
was published
Apr 24, 2023
Denial-of-service condition in M-Files Server versions before 25.11.15392.1 allows an...
High
Unreviewed
CVE-2025-11681
was published
Nov 17, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command
High
CVE-2018-21258
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
A vulnerability in the web-based management interface of affected products could allow an...
High
Unreviewed
CVE-2025-37161
was published
Nov 18, 2025
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
High
CVE-2024-0241
was published
for
encoded_id-rails
(RubyGems)
Oct 24, 2023
An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware...
Moderate
Unreviewed
CVE-2025-6599
was published
Nov 18, 2025
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
High
CVE-2025-6176
was published
for
Scrapy
(pip)
Oct 31, 2025
Liferay Portal Vulnerable to DoS via Crafted Headless API Request
High
CVE-2025-62260
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in...
High
Unreviewed
CVE-2021-4467
was published
Nov 15, 2025
ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2...
High
Unreviewed
CVE-2021-4465
was published
Nov 15, 2025
ProTip!
Advisories are also available from the
GraphQL API