GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
198 advisories
Filter by severity
@stablelib/cbor: Stack exhaustion Denial of Service via deeply nested CBOR arrays, maps, or tags
High
GHSA-5jg4-p4qw-cgfr
was published
for
@stablelib/cbor
(npm)
Apr 4, 2026
C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)
High
GHSA-wcjx-v2wj-xg87
was published
for
c2cciutils
(pip)
Mar 26, 2026
Scriban has Uncontrolled Recursion in `object.to_json` Causing Unrecoverable Process Crash via StackOverflowException
High
GHSA-xcx6-vp38-8hr5
was published
for
Scriban
(NuGet)
Mar 24, 2026
Scriban has a Stack Overflow via Nested Array Initializers That Bypass the ExpressionDepthLimit Fix
High
GHSA-p6q4-fgr8-vx4p
was published
for
Scriban
(NuGet)
Mar 24, 2026
cbor2 has a Denial of Service via Uncontrolled Recursion in cbor2.loads
High
CVE-2026-26209
was published
for
cbor2
(pip)
Mar 23, 2026
Parse Server LiveQuery subscription query depth bypass
High
CVE-2026-33508
was published
for
parse-server
(npm)
Mar 20, 2026
Parse Server has a query condition depth bypass via pre-validation transform pipeline
High
CVE-2026-33498
was published
for
parse-server
(npm)
Mar 20, 2026
Scriban has an Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service)
High
GHSA-grr9-747v-xvcp
was published
for
Scriban.Signed
(NuGet)
Mar 19, 2026
Scriban has Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service)
High
GHSA-wgh7-7m3c-fx25
was published
for
Scriban.Signed
(NuGet)
Mar 19, 2026
Parse Server crash via deeply nested query condition operators
High
CVE-2026-32944
was published
for
parse-server
(npm)
Mar 17, 2026
Denial of Service in pyasn1 via Unbounded Recursion
High
CVE-2026-30922
was published
for
pyasn1
(pip)
Mar 17, 2026
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
High
GHSA-v7cf-c9rm-wm3j
was published
for
justhtml
(pip)
Mar 17, 2026
AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion
High
CVE-2026-32933
was published
for
AutoMapper
(NuGet)
Mar 13, 2026
flatted vulnerable to unbounded recursion DoS in parse() revive phase
High
CVE-2026-32141
was published
for
flatted
(npm)
Mar 13, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2...
High
Unreviewed
CVE-2026-1069
was published
Mar 11, 2026
xgrammar vulnerable to DoS via multi-layer nesting
High
CVE-2026-25048
was published
for
xgrammar
(pip)
Mar 5, 2026
Multer Vulnerable to Denial of Service via Uncontrolled Recursion
High
CVE-2026-3520
was published
for
multer
(npm)
Mar 5, 2026
Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
High
CVE-2026-27601
was published
for
underscore
(npm)
Mar 3, 2026
A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09....
High
Unreviewed
CVE-2025-70957
was published
Feb 14, 2026
A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10....
High
Unreviewed
CVE-2025-70955
was published
Feb 14, 2026
MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce...
High
Unreviewed
CVE-2026-1849
was published
Feb 10, 2026
protobuf affected by a JSON recursion depth bypass
High
CVE-2026-0994
was published
for
protobuf
(pip)
Jan 23, 2026
Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all...
High
Unreviewed
CVE-2025-59789
was published
Dec 1, 2025
node-forge has ASN.1 Unbounded Recursion
High
CVE-2025-66031
was published
for
node-forge
(npm)
Nov 26, 2025
OpenSearch is vulnerable to DoS via complex query_string inputs
High
CVE-2025-9624
was published
for
org.opensearch:opensearch-common
(Maven)
Nov 25, 2025
ProTip!
Advisories are also available from the
GraphQL API