GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
433 advisories
Filter by severity
ratex-parser has unbounded parser recursion that leads to stack overflow (process abort)
Moderate
CVE-2026-53531
was published
for
ratex-parser
(Rust)
Jul 7, 2026
Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler
Moderate
GHSA-mxwc-wh95-pw4g
was published
for
trapster
(pip)
Jul 8, 2026
Protobuf: Unbounded recursion depth in embedded-message decoding
High
CVE-2026-54451
was published
for
protobuf
(Erlang)
Jul 15, 2026
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows...
High
Unreviewed
CVE-2026-38752
was published
Jul 16, 2026
A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers...
High
Unreviewed
CVE-2026-38755
was published
Jul 16, 2026
SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested...
High
Unreviewed
CVE-2024-58370
was published
Jul 18, 2026
SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when...
Moderate
Unreviewed
CVE-2025-71393
was published
Jul 18, 2026
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix dead ACL conflict...
High
Unreviewed
CVE-2026-53395
was published
Jul 19, 2026
SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated...
High
Unreviewed
CVE-2026-63737
was published
Jul 20, 2026
SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and...
High
Unreviewed
CVE-2026-63760
was published
Jul 20, 2026
SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when...
High
Unreviewed
CVE-2026-63759
was published
Jul 20, 2026
Axios: Excessive recursion in formDataToJSON can cause denial of service
Moderate
GHSA-42h9-826w-cgv3
was published
for
axios
(npm)
Jul 20, 2026
Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
Moderate
CVE-2026-59927
was published
for
mistune
(pip)
Jul 20, 2026
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer...
High
Unreviewed
CVE-2026-64194
was published
Jul 20, 2026
Axios form serializer maxDepth bypass via {} metatoken
Moderate
GHSA-hcpx-6fm6-wx23
was published
for
axios
(npm)
Jul 20, 2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially...
Moderate
Unreviewed
CVE-2026-63144
was published
Jul 22, 2026
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
Moderate
CVE-2026-55594
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Moderate
GHSA-r292-9mhp-454m
was published
for
tar
(npm)
Jul 24, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of...
High
Unreviewed
CVE-2026-16192
was published
Jul 28, 2026
The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs...
High
Unreviewed
CVE-2026-58178
was published
Jul 29, 2026
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an...
High
Unreviewed
CVE-2026-67215
was published
Jul 29, 2026
Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to...
High
Unreviewed
CVE-2026-67194
was published
Jul 29, 2026
axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing...
Moderate
Unreviewed
CVE-2026-67321
was published
Aug 1, 2026
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self...
High
Unreviewed
CVE-2026-59645
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard....
High
Unreviewed
CVE-2026-13506
was published
Aug 3, 2026
ProTip!
Advisories are also available from the
GraphQL API