GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
24 advisories
Filter by severity
Denial of Service in Elasticsearch
Moderate
CVE-2021-22144
was published
for
org.elasticsearch:elasticsearch
(Maven)
Aug 9, 2021
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
High
CVE-2021-45105
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Dec 18, 2021
Uncontrolled Recursion in Play Framework
High
CVE-2020-26883
was published
for
com.typesafe.play:play
(Maven)
Feb 10, 2022
Data Amplification in Play Framework
High
CVE-2020-26882
was published
for
com.typesafe.play:play
(Maven)
Feb 10, 2022
Logic error in Apache Pinot
High
CVE-2022-23974
was published
for
org.apache.pinot:pinot
(Maven)
Apr 6, 2022
Jenkins Token Macro Plugin's recursive token expansion results in information disclosure and DoS
Moderate
CVE-2019-1003011
was published
for
org.jenkins-ci.plugins:token-macro
(Maven)
May 13, 2022
Apache ORC vulnerable to Uncontrolled Recursion
High
CVE-2018-8015
was published
for
org.apache.orc:orc
(Maven)
May 13, 2022
Uncontrolled Recursion in Akka HTTP
High
CVE-2021-42697
was published
for
com.typesafe.akka:aakka-http-core_2.13.0-M3
(Maven)
May 24, 2022
Jettison memory exhaustion
High
CVE-2022-40150
was published
for
org.codehaus.jettison:jettison
(Maven)
Sep 17, 2022
HAProxyMessageDecoder Stack Exhaustion DoS
Moderate
CVE-2022-41881
was published
for
io.netty:netty-codec-haproxy
(Maven)
Dec 12, 2022
XStream can cause Denial of Service via stack overflow
High
CVE-2022-41966
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Dec 29, 2022
Jettison vulnerable to infinite recursion
High
CVE-2023-1436
was published
for
org.codehaus.jettison:jettison
(Maven)
Mar 22, 2023
json-smart Uncontrolled Recursion vulnerability
High
CVE-2023-1370
was published
for
net.minidev:json-smart
(Maven)
Mar 23, 2023
Karate has vulnerable dependency on json-smart package (CVE-2023-1370)
High
GHSA-5x5q-8cgm-2hjq
was published
for
com.intuit.karate:karate-core
(Maven)
Mar 31, 2023
hjson stack exhaustion vulnerability
High
CVE-2023-34620
was published
for
github.com/hjson/hjson-go/v4
(Composer)
Jun 14, 2023
Undertow Denial of Service vulnerability
High
CVE-2024-5971
was published
for
io.undertow:undertow-core
(Maven)
Jul 8, 2024
Netplex Json-smart Uncontrolled Recursion vulnerability
High
CVE-2024-57699
was published
for
net.minidev:json-smart
(Maven)
Feb 6, 2025
Wire has Uncontrolled Recursion on Nested Groups
Moderate
CVE-2024-58103
was published
for
com.squareup.wire:wire-runtime
(Maven)
Mar 16, 2025
Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
Moderate
CVE-2025-53864
was published
for
com.nimbusds:nimbus-jose-jwt
(Maven)
Jul 11, 2025
Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
Moderate
CVE-2025-48924
was published
for
commons-lang:commons-lang
(Maven)
Jul 11, 2025
OpenSearch is vulnerable to DoS via complex query_string inputs
High
CVE-2025-9624
was published
for
org.opensearch:opensearch-common
(Maven)
Nov 25, 2025
Apache Commons Configuration: StackOverflowError for YAML input with cycles
Moderate
CVE-2026-45205
was published
for
org.apache.commons:commons-configuration2
(Maven)
May 14, 2026
Spring Cloud Function Context has Uncontrolled Recursion
Moderate
CVE-2026-40989
was published
for
org.springframework.cloud:spring-cloud-function-context
(Maven)
Jun 1, 2026
ProTip!
Advisories are also available from the
GraphQL API