GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,466
Erlang
33
GitHub Actions
23
Go
2,166
Maven
5,000+
npm
3,830
NuGet
696
pip
3,507
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
460 advisories
Filter by severity
Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responses
High
CVE-2025-25293
was published
for
ruby-saml
(RubyGems)
Mar 12, 2025
Goroutine Leak in Abacus SSE Implementation
High
CVE-2025-27421
was published
for
github.com/jasonlovesdoggo/abacus
(Go)
Mar 3, 2025
Undertow Uncontrolled Resource Consumption Vulnerability
High
CVE-2024-1635
was published
for
io.undertow:undertow-core
(Maven)
Feb 20, 2024
.NET Denial of Service Vulnerability
High
CVE-2023-38180
was published
for
Microsoft.AspNetCore.App.Runtime.win-arm64
(NuGet)
Aug 9, 2023
Gophish vulnerable to Denial of Service via crafted payload involving autofocus
High
CVE-2022-45003
was published
for
github.com/gophish/gophish
(Go)
Mar 22, 2023
Undertow's url-encoded request path information can be broken on ajp-listener
High
CVE-2024-6162
was published
for
io.undertow:undertow-core
(Maven)
Jun 20, 2024
Denial of Service Vulnerability in ActiveRecord's PostgreSQL adapter
High
CVE-2022-44566
was published
for
activerecord
(RubyGems)
Jan 18, 2023
Apache CXF: Denial of Service vulnerability with temporary files
High
CVE-2025-23184
was published
for
org.apache.cxf:cxf-core
(Maven)
Jan 21, 2025
Apache Airflow denial of service vulnerability
High
CVE-2023-37379
was published
for
apache-airflow
(pip)
Aug 23, 2023
Traefik HTTP header parsing could cause a denial of service
High
CVE-2023-29013
was published
for
github.com/traefik/traefik/v2
(Go)
Apr 11, 2023
Rack has possible DoS Vulnerability in Multipart MIME parsing
High
CVE-2023-27530
was published
for
rack
(RubyGems)
Mar 8, 2023
Denial of service via header parsing in Rack
High
CVE-2022-44570
was published
for
rack
(RubyGems)
Jan 18, 2023
Uncontrolled Resource Consumption in ansi-html
High
CVE-2021-23424
was published
for
ansi-html
(npm)
Sep 2, 2021
axios Inefficient Regular Expression Complexity vulnerability
High
CVE-2021-3749
was published
for
axios
(npm)
Sep 1, 2021
Regular Expression Denial of Service (ReDoS)
High
GHSA-h6ch-v84p-w6p9
was published
for
diff
(npm)
Jun 13, 2019
Apache James vulnerable to denial of service through JMAP HTML to text conversion
High
CVE-2024-45626
was published
for
org.apache.james:james-server-jmap-draft
(Maven)
Feb 6, 2025
Connection leaking on idle timeout when TCP congested
High
CVE-2024-22201
was published
for
org.eclipse.jetty.http2:http2-common
(Maven)
Feb 26, 2024
Apache James vulnerable to denial of service through the use of IMAP literals
High
CVE-2024-37358
was published
for
org.apache.james.protocols:protocols-imap
(Maven)
Feb 6, 2025
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
High
CVE-2024-47554
was published
for
commons-io:commons-io
(Maven)
Oct 3, 2024
Uncontrolled Resource Consumption in moodle
High
CVE-2024-25978
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
go-git clients vulnerable to DoS via maliciously crafted Git server replies
High
CVE-2025-21614
was published
for
github.com/go-git/go-git
(Go)
Jan 6, 2025
htmlcleaner vulnerable to stack exhaustion
High
CVE-2023-34624
was published
for
net.sourceforge.htmlcleaner:htmlcleaner
(Maven)
Jun 14, 2023
jsonij vulnerable to stack exhaustion
High
CVE-2023-34614
was published
for
cc.plural:jsonij
(Maven)
Jun 14, 2023
ProTip!
Advisories are also available from the
GraphQL API