GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
807 advisories
Filter by severity
Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
High
CVE-2026-33116
was published
for
System.Security.Cryptography.Xml
(NuGet)
Apr 14, 2026
Stack overflow vulnerability in the media platform.
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2026-34852
was published
Apr 13, 2026
Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation...
Moderate
Unreviewed
CVE-2026-39934
was published
Apr 8, 2026
netavark has incorrect error handling for malformed tcp packets
High
CVE-2026-35406
was published
for
netavark
(Rust)
Apr 7, 2026
In the Linux kernel, the following vulnerability has been resolved:
serial: core: fix infinite...
Moderate
Unreviewed
CVE-2026-23472
was published
Apr 3, 2026
In the Linux kernel, the following vulnerability has been resolved:
bonding: prevent potential...
High
Unreviewed
CVE-2026-23451
was published
Apr 3, 2026
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix differential...
Moderate
Unreviewed
CVE-2026-23409
was published
Apr 1, 2026
XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion
High
CVE-2026-32287
was published
for
github.com/antchfx/xpath
(Go)
Mar 29, 2026
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
High
CVE-2026-33891
was published
for
node-forge
(npm)
Mar 26, 2026
pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream
Moderate
CVE-2026-33699
was published
for
pypdf
(pip)
Mar 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
can: ucan: Fix infinite loop...
Moderate
Unreviewed
CVE-2026-23298
was published
Mar 25, 2026
jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs
High
CVE-2026-4598
was published
for
jsrsasign
(npm)
Mar 23, 2026
Denial of service via non-terminating SYLT frame parsing loop in tinytag
Moderate
CVE-2026-32889
was published
for
tinytag
(pip)
Mar 19, 2026
UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
High
CVE-2026-32875
was published
for
ujson
(pip)
Mar 18, 2026
In the Linux kernel, the following vulnerability has been resolved:
fs: ntfs3: check return...
Moderate
Unreviewed
CVE-2025-71266
was published
Mar 18, 2026
In the Linux kernel, the following vulnerability has been resolved:
fs: ntfs3: fix infinite loop...
Moderate
Unreviewed
CVE-2025-71267
was published
Mar 18, 2026
In the Linux kernel, the following vulnerability has been resolved:
fs: ntfs3: fix infinite loop...
Moderate
Unreviewed
CVE-2025-71265
was published
Mar 18, 2026
music-metadata has an infinite loop vulnerability in ASF parser
High
CVE-2026-32256
was published
for
music-metadata
(npm)
Mar 17, 2026
Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices
High
CVE-2026-33013
was published
for
io.micronaut:micronaut-json-core
(Maven)
Mar 17, 2026
Denial of Service in pyasn1 via Unbounded Recursion
High
CVE-2026-30922
was published
for
pyasn1
(pip)
Mar 17, 2026
Loop with Unreachable Exit Condition ('Infinite Loop') in ewe
High
CVE-2026-32873
was published
for
ewe
(Erlang)
Mar 16, 2026
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Moderate
Unreviewed
CVE-2026-32777
was published
Mar 16, 2026
A flaw was identified in the RAR5 archive decompression logic of the libarchive library,...
High
Unreviewed
CVE-2026-4111
was published
Mar 13, 2026
file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header
Moderate
CVE-2026-31808
was published
for
file-type
(npm)
Mar 10, 2026
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a...
Moderate
Unreviewed
CVE-2025-69647
was published
Mar 9, 2026
ProTip!
Advisories are also available from the
GraphQL API