GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,466
Erlang
33
GitHub Actions
23
Go
2,166
Maven
5,000+
npm
3,830
NuGet
696
pip
3,507
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
101 advisories
Filter by severity
Undertow vulnerable to memory exhaustion due to buffer leak
High
CVE-2021-3690
was published
for
io.undertow:undertow-core
(Maven)
Jul 15, 2022
Apache Tapestry 5.8.1 vulnerable to ReDoS via Content Types causing catastrophic backtracking
High
CVE-2022-31781
was published
for
org.apache.tapestry:tapestry-core
(Maven)
Jul 14, 2022
Jetty vulnerable to Invalid HTTP/2 requests that can lead to denial of service
High
CVE-2022-2048
was published
for
org.eclipse.jetty.http2:http2-server
(Maven)
Jul 7, 2022
SystemDS CPU exhaustion vulnerability
High
CVE-2022-26477
was published
for
org.apache.systemds:systemds
(Maven)
Jun 28, 2022
Denial of service binding form from JSON in Play Framework
High
CVE-2022-31018
was published
for
com.typesafe.play:play_2.12
(Maven)
Jun 3, 2022
Undertow Uncontrolled Resource Consumption
High
CVE-2021-3629
was published
for
io.undertow:undertow-core
(Maven)
May 25, 2022
Undertow vulnerable to Uncontrolled Resource Consumption
High
CVE-2019-14888
was published
for
io.undertow:undertow-core
(Maven)
May 24, 2022
Ignite Realtime Openfire vulnerable to XMPPbomb attack
High
CVE-2014-2741
was published
for
org.igniterealtime.openfire:parent
(Maven)
May 17, 2022
Uncontrolled Resource Consumption in Apache Tomcat
High
CVE-2014-0230
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Apache OpenMeetings vulnerable to Uncontrolled Resource Consumption
High
CVE-2017-7684
was published
for
org.apache.openmeetings:openmeetings-parent
(Maven)
May 13, 2022
Red Hat Wildfly DoS
High
CVE-2016-9589
was published
for
org.wildfly:wildfly-undertow
(Maven)
May 13, 2022
Command Injection in VIVO Vitro
High
CVE-2019-6986
was published
for
org.vivoweb:vitro-project
(Maven)
May 13, 2022
Uncontrolled Resource Consumption in Artemis and HornetQ
High
CVE-2017-12174
was published
for
org.apache.activemq:artemis-native
(Maven)
May 13, 2022
Uncontrolled Resource Consumption in Apache ZooKeeper
High
CVE-2017-5637
was published
for
org.apache.zookeeper:zookeeper
(Maven)
May 13, 2022
Apache Geronimo Hash Collisions Cause DoS
High
CVE-2011-5034
was published
for
org.apache.geronimo:geronimo
(Maven)
May 13, 2022
Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption
High
CVE-2022-29885
was published
for
org.apache.tomcat:tomcat
(Maven)
May 13, 2022
OutOfMemory Exception by specifically crafted processing instruction in NekoHtml Parser
High
CVE-2022-29546
was published
for
net.sourceforge.htmlunit:neko-htmlunit
(Maven)
Apr 26, 2022
Uncontrolled Resource Consumption in Apache DolphinScheduler
High
CVE-2022-25598
was published
for
apache-dolphinscheduler
(Maven)
Mar 31, 2022
RESTEasy 4.5.5.Final in hash flooding
High
CVE-2020-14326
was published
for
org.jboss.resteasy:resteasy-bom
(Maven)
Mar 18, 2022
Uncontrolled Resource Consumption in jboss-remoting
High
CVE-2020-35510
was published
for
org.jboss.remoting:jboss-remoting
(Maven)
Mar 18, 2022
Denial of service in Apache OpenMeetings
High
CVE-2020-13951
was published
for
org.apache.openmeetings:openmeetings-parent
(Maven)
Feb 10, 2022
Uncontrolled Resource Consumption in Apache Tomcat
High
CVE-2020-11996
was published
for
org.apache.tomcat:tomcat
(Maven)
Feb 9, 2022
Denial of service in Undertow
High
CVE-2020-27782
was published
for
io.undertow:undertow-core
(Maven)
Feb 9, 2022
Apache ActiveMQ Artemis Uncontrolled Resource Consumption (DoS)
High
CVE-2022-23913
was published
for
org.apache.activemq:artemis-core-client
(Maven)
Feb 6, 2022
Denial of Service by injecting highly recursive collections or maps in XStream
High
CVE-2021-43859
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Feb 1, 2022
ProTip!
Advisories are also available from the
GraphQL API