GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
198 advisories
Filter by severity
** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy.
This issue...
High
Unreviewed
CVE-2026-61483
was published
Aug 5, 2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError...
High
Unreviewed
CVE-2026-68073
was published
Aug 5, 2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError...
High
Unreviewed
CVE-2026-66274
was published
Aug 5, 2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError...
High
Unreviewed
CVE-2026-67590
was published
Aug 5, 2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError...
High
Unreviewed
CVE-2026-67552
was published
Aug 5, 2026
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard....
High
Unreviewed
CVE-2026-13506
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self...
High
Unreviewed
CVE-2026-59645
was published
Aug 3, 2026
Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to...
High
Unreviewed
CVE-2026-67194
was published
Jul 29, 2026
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an...
High
Unreviewed
CVE-2026-67215
was published
Jul 29, 2026
The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs...
High
Unreviewed
CVE-2026-58178
was published
Jul 29, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of...
High
Unreviewed
CVE-2026-16192
was published
Jul 28, 2026
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer...
High
Unreviewed
CVE-2026-64194
was published
Jul 20, 2026
SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and...
High
Unreviewed
CVE-2026-63760
was published
Jul 20, 2026
SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when...
High
Unreviewed
CVE-2026-63759
was published
Jul 20, 2026
SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated...
High
Unreviewed
CVE-2026-63737
was published
Jul 20, 2026
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix dead ACL conflict...
High
Unreviewed
CVE-2026-53395
was published
Jul 19, 2026
SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested...
High
Unreviewed
CVE-2024-58370
was published
Jul 18, 2026
A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers...
High
Unreviewed
CVE-2026-38755
was published
Jul 16, 2026
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows...
High
Unreviewed
CVE-2026-38752
was published
Jul 16, 2026
Protobuf: Unbounded recursion depth in embedded-message decoding
High
CVE-2026-54451
was published
for
protobuf
(Erlang)
Jul 15, 2026
pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu...
High
Unreviewed
CVE-2026-38970
was published
Jul 2, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
High
GHSA-q729-696q-g9pq
was published
for
surrealdb
(Rust)
Jul 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Use...
High
Unreviewed
CVE-2026-53329
was published
Jul 1, 2026
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
High
CVE-2026-49451
was published
for
Microsoft.OpenAPI
(NuGet)
Jun 30, 2026
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
High
CVE-2026-48506
was published
for
MessagePack
(NuGet)
Jun 25, 2026
ProTip!
Advisories are also available from the
GraphQL API