GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,722
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,568
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
40 advisories
Filter by severity
smol-toml: Denial of Service via malformed TOML documents
High
CVE-2026-85730
was published
for
smol-toml
(npm)
Sep 9, 2026
Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that...
High
Unreviewed
CVE-2026-13761
was published
Aug 28, 2026
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality....
Moderate
Unreviewed
CVE-2026-16599
was published
Aug 25, 2026
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability
High
CVE-2026-62901
was published
for
Microsoft.NETCore.App.Runtime.linux-arm
(NuGet)
Aug 11, 2026
Mermaid radar diagrams are vulnerable to DoS
Moderate
CVE-2026-71439
was published
for
mermaid
(npm)
Aug 6, 2026
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the...
High
Unreviewed
CVE-2026-20301
was published
Aug 5, 2026
An authenticated attacker can craft a disposition frame with large or illegal ranges causing...
Moderate
Unreviewed
CVE-2026-67554
was published
Aug 5, 2026
An authenticated attacker can craft a disposition frame with large or illegal ranges causing...
Moderate
Unreviewed
CVE-2026-66276
was published
Aug 5, 2026
An authenticated attacker can craft a disposition frame with large or illegal ranges causing...
Moderate
Unreviewed
CVE-2026-68077
was published
Aug 5, 2026
Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L...
Moderate
Unreviewed
CVE-2026-55731
was published
Jul 24, 2026
An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of...
High
Unreviewed
CVE-2026-33800
was published
Jul 9, 2026
FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial...
Moderate
Unreviewed
CVE-2026-15172
was published
Jul 8, 2026
kafka-python vulnerable to denial of service through an unbounded SCRAM iteration count
High
CVE-2026-10143
was published
for
kafka-python
(pip)
Jun 11, 2026
Logic bypass vulnerability in the file system. Impact: Successful exploitation of this...
Low
Unreviewed
CVE-2026-41986
was published
Jun 9, 2026
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS...
Moderate
Unreviewed
CVE-2026-27145
was published
Jun 3, 2026
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad...
Moderate
Unreviewed
CVE-2026-5950
was published
May 20, 2026
A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables...
Moderate
Unreviewed
CVE-2026-0243
was published
May 13, 2026
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger...
High
Unreviewed
CVE-2026-39820
was published
May 7, 2026
Uncontrolled Recursion vulnerability in Apache Thrift.
This issue affects Apache Thrift: before...
Moderate
Unreviewed
CVE-2026-41606
was published
Apr 28, 2026
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the...
High
Unreviewed
CVE-2026-1519
was published
Mar 25, 2026
Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to...
Moderate
Unreviewed
CVE-2019-25624
was published
Mar 23, 2026
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated...
High
Unreviewed
CVE-2026-27689
was published
Mar 10, 2026
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated...
High
Unreviewed
CVE-2026-23689
was published
Feb 10, 2026
Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS)...
High
Unreviewed
CVE-2025-65518
was published
Jan 8, 2026
Liferay Portal has unchecked input for loop condition vulnerability in XML-RPC
Moderate
CVE-2025-43801
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 16, 2025
ProTip!
Advisories are also available from the
GraphQL API