GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
20 advisories
Filter by severity
Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing
Moderate
CVE-2024-1899
was published
for
showdown
(npm)
Feb 26, 2024
KaTeX's maxExpand bypassed by `\edef`
Moderate
CVE-2024-28243
was published
for
katex
(npm)
Mar 25, 2024
KaTeX's maxExpand bypassed by Unicode sub/superscripts
Moderate
CVE-2024-28244
was published
for
katex
(npm)
Mar 25, 2024
matrix-js-sdk will freeze when a user sets a room with itself as a its predecessor
Moderate
CVE-2024-42369
was published
for
matrix-js-sdk
(npm)
Aug 20, 2024
Denial of Service condition in Next.js image optimization
Moderate
CVE-2024-47831
was published
for
next
(npm)
Oct 14, 2024
smol-toml has a Denial of Service via malicious TOML document using deeply nested inline tables
Moderate
GHSA-pqhp-25j4-6hq9
was published
for
smol-toml
(npm)
Nov 22, 2024
Duplicate Advisory: express-xss-sanitizer has an unbounded recursion depth
Moderate
GHSA-qhwp-454g-2gv4
was published
for
express-xss-sanitizer
(npm)
Sep 15, 2025
•
withdrawn
express-xss-sanitizer has an unbounded recursion depth
Moderate
CVE-2025-59364
was published
for
express-xss-sanitizer
(npm)
Sep 26, 2025
Duplicate Advisory: Nodemailer is vulnerable to DoS through Uncontrolled Recursion
Moderate
GHSA-46j5-6fg5-4gv3
was published
for
nodemailer
(npm)
Dec 18, 2025
•
withdrawn
Withdrawn Advisory: eslint has a Stack Overflow when serializing objects with circular references
Moderate
CVE-2025-50537
was published
for
eslint
(npm)
Jan 26, 2026
•
withdrawn
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
Moderate
CVE-2026-33532
was published
for
yaml
(npm)
Mar 25, 2026
smol-toml: Denial of Service via TOML documents containing thousands of consecutive commented lines
Moderate
GHSA-v3rj-xjv7-4jmq
was published
for
smol-toml
(npm)
Mar 25, 2026
SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parser
Moderate
CVE-2026-34211
was published
for
@nyariv/sandboxjs
(npm)
Apr 3, 2026
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
Moderate
CVE-2026-42039
was published
for
axios
(npm)
May 5, 2026
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
Moderate
CVE-2026-45740
was published
for
protobufjs
(npm)
May 19, 2026
protobufjs : Schema-derived names can shadow runtime-significant properties
Moderate
CVE-2026-54269
was published
for
protobufjs
(npm)
Jun 15, 2026
Axios: Excessive recursion in formDataToJSON can cause denial of service
Moderate
GHSA-42h9-826w-cgv3
was published
for
axios
(npm)
Jul 20, 2026
Axios form serializer maxDepth bypass via {} metatoken
Moderate
GHSA-hcpx-6fm6-wx23
was published
for
axios
(npm)
Jul 20, 2026
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Moderate
GHSA-r292-9mhp-454m
was published
for
tar
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API