GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
32 advisories
Filter by severity
Denial of Service in pyasn1 via Unbounded Recursion
High
CVE-2026-30922
was published
for
pyasn1
(pip)
Mar 17, 2026
Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
Moderate
CVE-2026-59927
was published
for
mistune
(pip)
Jul 20, 2026
Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler
Moderate
GHSA-mxwc-wh95-pw4g
was published
for
trapster
(pip)
Jul 8, 2026
SQLFluff: Recursive Stack Overflow in Parser
High
CVE-2026-46373
was published
for
sqlfluff
(pip)
May 19, 2026
Strawberry GraphQL has a Circular Fragment Reference DOS
Moderate
CVE-2026-47706
was published
for
strawberry-graphql
(pip)
Jun 4, 2026
eml_parser has recursion DoS via nested message/rfc822 attachments
Moderate
CVE-2026-44844
was published
for
eml_parser
(pip)
May 8, 2026
FastFeedParser has an infinite redirect loop DoS via meta-refresh chain
High
CVE-2026-39376
was published
for
fastfeedparser
(pip)
Apr 8, 2026
zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service
Moderate
CVE-2026-47180
was published
for
zeroconf
(pip)
May 29, 2026
C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)
High
GHSA-wcjx-v2wj-xg87
was published
for
c2cciutils
(pip)
Mar 26, 2026
cbor2 has a Denial of Service via Uncontrolled Recursion in cbor2.loads
High
CVE-2026-26209
was published
for
cbor2
(pip)
Mar 23, 2026
Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS
Moderate
GHSA-rf74-v2fm-23pw
was published
for
nltk
(pip)
Mar 18, 2026
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
High
GHSA-v7cf-c9rm-wm3j
was published
for
justhtml
(pip)
Mar 17, 2026
orjson does not limit recursion for deeply nested JSON documents
High
CVE-2024-27454
was published
for
orjson
(pip)
Feb 26, 2024
xgrammar vulnerable to DoS via multi-layer nesting
High
CVE-2026-25048
was published
for
xgrammar
(pip)
Mar 5, 2026
protobuf affected by a JSON recursion depth bypass
High
CVE-2026-0994
was published
for
protobuf
(pip)
Jan 23, 2026
LlamaIndex Vulnerable to Denial of Service (DoS)
High
CVE-2025-1752
was published
for
llama-index
(pip)
May 10, 2025
LlamaIndex Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2024-12910
was published
for
llama-index
(pip)
Mar 20, 2025
XGrammar affected by Denial of Service by infinite recursion grammars
High
CVE-2025-57809
was published
for
xgrammar
(pip)
Aug 25, 2025
LlamaIndex affected by a Denial of Service (DOS) in JSONReader
High
CVE-2025-5302
was published
for
llama-index-core
(pip)
Aug 26, 2025
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
Moderate
CVE-2025-5472
was published
for
llama-index-core
(pip)
Jul 7, 2025
protobuf-python has a potential Denial of Service issue
High
CVE-2025-4565
was published
for
protobuf
(pip)
Jun 16, 2025
Stack overflow in `ParseAttrValue` with nested tensors
Low
CVE-2021-29615
was published
for
tensorflow
(pip)
May 21, 2021
Denial of service in langchain-community
Moderate
CVE-2024-2965
was published
for
langchain
(pip)
Jun 6, 2024
Stack overflow due to looping TFLite subgraph
High
CVE-2021-29591
was published
for
tensorflow
(pip)
May 21, 2021
ProTip!
Advisories are also available from the
GraphQL API