GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,466
Erlang
33
GitHub Actions
23
Go
2,166
Maven
5,000+
npm
3,830
NuGet
696
pip
3,507
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
180 advisories
Filter by severity
jose4j denial of service via specifically crafted JWE
Moderate
CVE-2023-51775
was published
for
org.bitbucket.b_c:jose4j
(Maven)
Feb 29, 2024
Connection leaking on idle timeout when TCP congested
High
CVE-2024-22201
was published
for
org.eclipse.jetty.http2:http2-common
(Maven)
Feb 26, 2024
Liferay Portal vulnerable to Denial of Service
Moderate
CVE-2024-26265
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Feb 20, 2024
Undertow Uncontrolled Resource Consumption Vulnerability
High
CVE-2024-1635
was published
for
io.undertow:undertow-core
(Maven)
Feb 20, 2024
Denial of Service in Connect2id Nimbus JOSE+JWT
High
CVE-2023-52428
was published
for
com.nimbusds:nimbus-jose-jwt
(Maven)
Feb 11, 2024
Liferay Portal denial of service (memory consumption)
High
CVE-2024-25143
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Feb 7, 2024
XWiki vulnerable to Denial of Service attack through attachments
High
CVE-2024-21651
was published
for
org.xwiki.platform:xwiki-platform-distribution-war
(Maven)
Jan 8, 2024
Grails data binding causes JVM crash and/or other denial of service
Moderate
CVE-2023-46131
was published
for
org.grails:grails-databinding
(Maven)
Dec 20, 2023
Grackle has StackOverflowError in GraphQL query processing
High
CVE-2023-50730
was published
for
edu.gemini:gsp-graphql-core_2.13
(Maven)
Dec 18, 2023
Bouncy Castle Denial of Service (DoS)
Moderate
CVE-2023-33202
was published
for
org.bouncycastle:bcpkix-jdk18on
(Maven)
Nov 23, 2023
Elasticsearch vulnerable to Uncontrolled Resource Consumption
High
CVE-2023-31418
was published
for
org.elasticsearch:elasticsearch
(Maven)
Oct 26, 2023
RabbitMQ Java client's Lack of Message Size Limitation leads to Remote DoS Attack
Moderate
CVE-2023-46120
was published
for
com.rabbitmq:amqp-client
(Maven)
Oct 24, 2023
OpenSearch uncontrolled resource consumption
High
GHSA-8wx3-324g-w4qq
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Oct 17, 2023
io.netty:netty-codec-http2 vulnerable to HTTP/2 Rapid Reset Attack
High
GHSA-xpw8-rcwv-8f8p
was published
for
io.netty:netty-codec-http2
(Maven)
Oct 10, 2023
HTTP/2 Stream Cancellation Attack
Moderate
CVE-2023-44487
was published
for
com.typesafe.akka:akka-http-core
(Go)
Oct 10, 2023
Undertow vulnerable to denial of service
High
CVE-2023-3223
was published
for
io.undertow:undertow-parent
(Maven)
Sep 27, 2023
Apache Commons Compress denial of service vulnerability
Moderate
CVE-2023-42503
was published
for
org.apache.commons:commons-compress
(Maven)
Sep 14, 2023
Esoteric YamlBeans XML Entity Expansion vulnerability
Moderate
CVE-2023-24620
was published
for
com.esotericsoftware.yamlbeans:yamlbeans
(Maven)
Aug 25, 2023
Denial of service in jackson-dataformats-text
High
CVE-2023-3894
was published
for
com.fasterxml.jackson.dataformat:jackson-dataformats-text
(Maven)
Aug 8, 2023
Apache Any23 vulnerable to excessive memory usage
Moderate
CVE-2023-34150
was published
for
org.apache.any23:apache-any23
(Maven)
Jul 5, 2023
FastAsyncWorldEdit vulnerable to Uncontrolled Resource Consumption
Moderate
CVE-2023-35925
was published
for
com.fastasyncworldedit:FastAsyncWorldEdit-Bukkit
(Maven)
Jun 22, 2023
org.nokogiri:nekohtml vulnerable to Uncontrolled Resource Consumption
High
CVE-2022-24839
was published
for
org.nokogiri:nekohtml
(Maven)
Jun 22, 2023
netty-handler SniHandler 16MB allocation
Moderate
CVE-2023-34462
was published
for
io.netty:netty-handler
(Maven)
Jun 20, 2023
jjson vulnerable to stack exhaustion
High
CVE-2023-35110
was published
for
de.grobmeier.json:jjson
(Maven)
Jun 14, 2023
JSONUtil vulnerable to stack exhaustion
High
CVE-2023-34615
was published
for
net.pwall.json:jsonutil
(Maven)
Jun 14, 2023
ProTip!
Advisories are also available from the
GraphQL API