GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
48 advisories
Filter by severity
pypdf: Possible long runtimes/large memory usage when retrieving outlines
Moderate
CVE-2026-84310
was published
for
pypdf
(pip)
Sep 1, 2026
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
Moderate
CVE-2026-45822
was published
for
decode-uri-component
(npm)
Aug 31, 2026
Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes...
High
Unreviewed
CVE-2026-54874
was published
Aug 25, 2026
An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by...
Moderate
Unreviewed
CVE-2026-23930
was published
Aug 18, 2026
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by...
Moderate
Unreviewed
CVE-2026-23934
was published
Aug 18, 2026
league/commonmark: Denial of service via deeply nested XML output
Moderate
GHSA-mj63-m3rc-8ppr
was published
for
league/commonmark
(Composer)
Aug 6, 2026
UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to...
High
Unreviewed
CVE-2026-54224
was published
Jun 18, 2026
Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of...
Moderate
Unreviewed
CVE-2026-8594
was published
May 30, 2026
Nerdbank.MessagePack has a memory amplification DoS in collection deserialization
Moderate
GHSA-qjvr-435c-5fjh
was published
for
Nerdbank.MessagePack
(NuGet)
May 29, 2026
Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY...
Moderate
Unreviewed
CVE-2026-45557
was published
May 19, 2026
Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling
Moderate
GHSA-36cp-mh65-x882
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenClaw has incomplete Fix for CVE-2026-32011: Feishu Webhook Pre-Auth Body Parsing DoS (Slow-Body / Slowloris Variant)
Moderate
CVE-2026-35665
was published
for
openclaw
(npm)
Mar 30, 2026
Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.
Moderate
Unreviewed
CVE-2025-46598
was published
Mar 20, 2026
A series of specifically crafted, unauthenticated messages can exhaust available memory and crash...
High
Unreviewed
CVE-2026-25611
was published
Feb 10, 2026
SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker...
Moderate
Unreviewed
CVE-2026-24324
was published
Feb 10, 2026
SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted...
High
Unreviewed
CVE-2026-0485
was published
Feb 10, 2026
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the...
Moderate
Unreviewed
CVE-2025-49643
was published
Dec 1, 2025
Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse
High
CVE-2026-22774
was published
for
devalue
(npm)
Jan 15, 2026
devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse
High
CVE-2026-22775
was published
for
devalue
(npm)
Jan 15, 2026
Marshmallow has DoS in Schema.load(many)
Moderate
CVE-2025-68480
was published
for
marshmallow
(pip)
Dec 22, 2025
SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security...
Moderate
Unreviewed
CVE-2025-42873
was published
Dec 9, 2025
Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials...
High
Unreviewed
CVE-2025-42876
was published
Dec 9, 2025
SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high...
High
Unreviewed
CVE-2025-42874
was published
Dec 9, 2025
This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of...
High
Unreviewed
CVE-2025-22166
was published
Oct 21, 2025
Sigstore Timestamp Authority allocates excessive memory during request parsing
High
CVE-2025-66564
was published
for
github.com/sigstore/timestamp-authority
(Go)
Dec 5, 2025
ProTip!
Advisories are also available from the
GraphQL API