GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
433 advisories
Filter by severity
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library...
Critical
Unreviewed
CVE-2026-32327
was published
Aug 6, 2026
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an...
Moderate
Unreviewed
CVE-2026-15996
was published
Aug 5, 2026
** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy.
This issue...
High
Unreviewed
CVE-2026-61483
was published
Aug 5, 2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError...
High
Unreviewed
CVE-2026-68073
was published
Aug 5, 2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError...
High
Unreviewed
CVE-2026-66274
was published
Aug 5, 2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError...
High
Unreviewed
CVE-2026-67590
was published
Aug 5, 2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError...
High
Unreviewed
CVE-2026-67552
was published
Aug 5, 2026
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
GeoDjango's `django...
Moderate
Unreviewed
CVE-2026-15830
was published
Aug 4, 2026
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard....
High
Unreviewed
CVE-2026-13506
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self...
High
Unreviewed
CVE-2026-59645
was published
Aug 3, 2026
axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing...
Moderate
Unreviewed
CVE-2026-67321
was published
Aug 1, 2026
Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to...
High
Unreviewed
CVE-2026-67194
was published
Jul 29, 2026
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an...
High
Unreviewed
CVE-2026-67215
was published
Jul 29, 2026
The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs...
High
Unreviewed
CVE-2026-58178
was published
Jul 29, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of...
High
Unreviewed
CVE-2026-16192
was published
Jul 28, 2026
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Moderate
GHSA-r292-9mhp-454m
was published
for
tar
(npm)
Jul 24, 2026
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
Moderate
CVE-2026-55594
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially...
Moderate
Unreviewed
CVE-2026-63144
was published
Jul 22, 2026
Axios form serializer maxDepth bypass via {} metatoken
Moderate
GHSA-hcpx-6fm6-wx23
was published
for
axios
(npm)
Jul 20, 2026
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer...
High
Unreviewed
CVE-2026-64194
was published
Jul 20, 2026
Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
Moderate
CVE-2026-59927
was published
for
mistune
(pip)
Jul 20, 2026
Axios: Excessive recursion in formDataToJSON can cause denial of service
Moderate
GHSA-42h9-826w-cgv3
was published
for
axios
(npm)
Jul 20, 2026
SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and...
High
Unreviewed
CVE-2026-63760
was published
Jul 20, 2026
SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when...
High
Unreviewed
CVE-2026-63759
was published
Jul 20, 2026
SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated...
High
Unreviewed
CVE-2026-63737
was published
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API