GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
118 advisories
Filter by severity
OpenFGA Vulnerable to DoS from circular relationship definitions
Moderate
CVE-2023-43645
was published
for
github.com/openfga/openfga
(Go)
Sep 28, 2023
x/net/html Vulnerable to DoS During HTML Parsing
High
CVE-2018-17846
was published
for
golang.org/x/net
(Go)
Sep 25, 2023
Undertow denial of service vulnerability
High
CVE-2023-1108
was published
for
io.undertow:undertow-core
(Maven)
Sep 14, 2023
FaucetSDN Ryu Denial of Service Vulnerability
High
CVE-2020-35141
was published
for
ryu
(pip)
Aug 11, 2023
FaucetSDN Ryu Denial of Service Vulnerability
High
CVE-2020-35139
was published
for
ryu
(pip)
Aug 11, 2023
PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects
Moderate
CVE-2023-36807
was published
for
PyPDF2
(pip)
Jun 30, 2023
pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character
Moderate
CVE-2023-36464
was published
for
PyPDF2
(pip)
Jun 30, 2023
OpenFGA vulnerable to denial of service due to circular relationship
Moderate
CVE-2023-35933
was published
for
github.com/openfga/openfga
(Go)
Jun 28, 2023
SwiftNIO Extras vulnerable to improper detection of complete HTTP body decompression
High
CVE-2022-3252
was published
for
github.com/apple/swift-nio-extras
(Swift)
Jun 7, 2023
phpseclib Infinite Loop vulnerability
Moderate
CVE-2023-27560
was published
for
phpseclib/phpseclib
(Composer)
Mar 3, 2023
Improper calculations in ECC implementation can trigger a Denial-of-Service (DoS)
High
CVE-2023-25653
was published
for
node-jose
(npm)
Feb 16, 2023
DoS vulnerability in MaliciousCode filter
Moderate
CVE-2023-23617
was published
for
openmage/magento-lts
(Composer)
Jan 27, 2023
socks Infinite Loop vulnerability
High
CVE-2013-10005
was published
for
github.com/btcsuite/go-socks
(Go)
Dec 28, 2022
linux-loader reading beyond EOF could lead to infinite loop
Low
CVE-2022-23523
was published
for
linux-loader
(Rust)
Dec 12, 2022
kamadak-exif vulnerable to Infinite loop when parsing PNG files
Moderate
CVE-2021-21235
was published
for
kamadak-exif
(Rust)
Oct 6, 2022
Apache Avro Rust SDK vulnerable to reader looping in cycle endlessly, consuming CPU
High
CVE-2022-35724
was published
for
apache-avro
(Rust)
Aug 10, 2022
file-type vulnerable to Infinite Loop via malformed MKV file
High
CVE-2022-36313
was published
for
file-type
(npm)
Jul 22, 2022
Security Update for the OPC UA .NET Standard Stack
High
CVE-2022-29862
was published
for
OPCFoundation.NetStandard.Opc.Ua.Core
(NuGet)
Jun 17, 2022
Pion DTLS Header reconstruction method can be thrown into an infinite loop
High
CVE-2022-29190
was published
for
github.com/pion/dtls
(Go)
May 24, 2022
Istio vulnerable to denial of service
High
CVE-2019-18817
was published
for
istio.io/istio
(Go)
May 24, 2022
Routinator infinite loop vulnerability
High
CVE-2021-43172
was published
for
routinator
(Rust)
May 24, 2022
golang.org/x/net/html Infinite Loop vulnerability
High
CVE-2021-33194
was published
for
golang.org/x/net
(Go)
May 24, 2022
StackStorm st2 Infinite Loop Condition
High
CVE-2021-28667
was published
for
st2client
(pip)
May 24, 2022
•
withdrawn
Designate does not enforce the DNS protocol limit concerning record set sizes
Moderate
CVE-2015-5694
was published
for
designate
(pip)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API